Skip to content
sandadocs

MCP and agents

Connect Claude, ChatGPT or another MCP client to your semantic fluid, with scoped permissions, approvals and a record of every call.

The Model Context Protocol (MCP) is an open standard that lets an AI assistant call tools on another system. Every sanda workspace is an MCP server. Point Claude, ChatGPT or an agent of your own at it, and the assistant can find your agreed metrics, look closely at a table, and get rows back for a question, without a database connection and without guessing what "revenue" means.

The server is one address for every workspace. Who is asking decides which workspace answers.

Text
https://console.sanda-os.com.au/api/mcp

What an assistant gets

An assistant reads through the semantic fluid, not through your warehouse directly. It names what it wants by reference (a metric, a dimension, a filter) and sanda composes the SQL, resolves the joins and runs it. The number that comes back is your workspace's own definition of that number, the same one sanda's chat and your reports use.

Asking questions is the baseline. Anything more is a permission that someone grants on purpose:

Permission What it lets an assistant do
Ask questions (on every integration token, and ticked by default when you connect an app) Find metrics, dimensions and tables, describe a table, run composed queries, search the text inside rows, look up how sanda works in these docs
Run its own SQL Send a read-only SELECT when the fluid cannot express a question
See connections and warehouses Check whether data is fresh and how full a warehouse is
Start a sync Run a connection now
Write the fluid Put tables on the map and define metrics, dimensions and filters, live at once
Load and add rows Land tables of its own rows, or append to tables you have opened for intake
Define views and procedures Build and schedule derived views on your compute
Run and commit SQL One statement at a time, committed, with no undo
Manage search Create and rebuild sanda search services
Email reports Schedule report deliveries and send them

An assistant can also look up how sanda works. The search_docs tool searches these docs, the same ones you are reading, and returns the matching sections with their links, so an assistant can answer "how do I connect a source?" from the page rather than from memory. It reads no data of yours, needs only fluid:read and costs nothing on the AI limit.

The full list is in scopes, and every tool, with its parameters, is in the MCP tool reference.

What an assistant cannot do

Nothing here widens what sanda can see. It changes who is holding the map.

  • It reads only what you have modelled and accepted. Proposals waiting for review are not visible, and neither is a table that is not on the map.
  • Questions go through a read-only role. Raw landed data, other workspaces and anything outside the accepted fluid are out of reach, whatever SQL an assistant writes. The permissions that write are the exception, and each says so in plain words on the consent screen.
  • Answers are capped. A question returns at most 50 rows, and each statement has a timeout.
  • A tool it may not use is not offered. It is absent from the tool list rather than present and refusing, so an assistant never tries what it cannot do.
  • It never sees a credential. Connection lists and warehouse lists never include a password or connection string.
  • Writes exist only behind a permission. A connection that was only granted questions cannot change anything.

Two ways to connect

Sign in with OAuth Hold an integration token
For A person connecting an assistant such as Claude or ChatGPT to their own workspace A machine: Claude Code, the Claude API, an agent harness of your own
Set up by Pressing Allow on sanda's consent screen An owner or admin creating a token and pasting it into the client
Acts for The person who approved it The owner or admin who created it
Ends when You disconnect it, or you leave the workspace The token is revoked or expires, or its creator leaves the workspace

If a client offers both, use OAuth: there is no secret to store. Step by step:

Editions

MCP and agents are included on every edition, and on a trial. The search tools need sanda search, which is included from Standard. The Excel and Power BI feed and its tokens work on every edition. See editions.

sanda search tools follow sanda search, which is also on Standard and Enterprise.

Watch what agents do

Open Intelligence · Agents in the console. Every member can see it. It answers the question the credential screen cannot: is it working?

  • Harness lists four things that must be true before an agent can do anything: a healthy warehouse, definitions on the map, a live credential, and (optionally) text an agent can search. Each one that is not true links to the page that fixes it.
  • Agents has one row per integration token or connected app, with what each may do in plain sentences, the permissions that go beyond asking questions marked, and when it was last used.
  • Activity has four tabs. Sessions groups one credential's calls with no gap of 15 minutes or more, because MCP holds no session of its own. Calls is the live feed. Refused lists what sanda declined to run at all, such as an unknown tool or a missing permission. By tool shows which tools are leaned on and which keep answering no.
  • Approvals, for owners and admins, holds the risky actions an agent asked for until a person decides.

A tool that answers no and a request sanda refuses are different things. An answer of no ran and explained itself in a sentence the assistant can act on ("those two tables fan out"). A refusal means sanda declined to run the tool: an unknown tool, a permission the credential does not hold, or a protocol mistake by the client. Refused is the tab to read when an assistant says it cannot see anything.

The activity feed shows that a call happened and how it went. It does not keep the rows that came back.

Every action is recorded and approvable

Every tool call is recorded with the credential that made it, the tool, how long it took and whether it answered no. Changes an agent makes go through the same handlers as the console's own buttons, with the same validation and the same audit record, so a metric an assistant defines is checked exactly as one you define yourself.

For the few actions that cannot be undone (committing SQL, dropping a view or a search service, emailing a report to an address outside your members' email domains), an owner or admin can require a person to approve first. The action waits, the owners and admins are emailed, and nothing runs until someone presses Approve and run. Approval is off by default. See permissions and approvals.

cherry is not MCP

cherry, sanda's own agent, lives in the console and is on every edition. It uses many of the same tools under your own role, with its own approval rules. See cherry.

Something unclear or out of date? Tell us, and we will fix the page.