MCP and agents
Connect Claude, ChatGPT or another MCP client to your semantic fluid, with scoped permissions, approvals and a record of every call.
The Model Context Protocol (MCP) is an open standard that lets an AI assistant call tools on another system. Every sanda workspace is an MCP server. Point Claude, ChatGPT or an agent of your own at it, and the assistant can find your agreed metrics, look closely at a table, and get rows back for a question, without a database connection and without guessing what "revenue" means.
The server is one address for every workspace. Who is asking decides which workspace answers.
https://console.sanda-os.com.au/api/mcpWhat an assistant gets
An assistant reads through the semantic fluid, not through your warehouse directly. It names what it wants by reference (a metric, a dimension, a filter) and sanda composes the SQL, resolves the joins and runs it. The number that comes back is your workspace's own definition of that number, the same one sanda's chat and your reports use.
Asking questions is the baseline. Anything more is a permission that someone grants on purpose:
| Permission | What it lets an assistant do |
|---|---|
| Ask questions (on every integration token, and ticked by default when you connect an app) | Find metrics, dimensions and tables, describe a table, run composed queries, search the text inside rows, look up how sanda works in these docs |
| Run its own SQL | Send a read-only SELECT when the fluid cannot express a question |
| See connections and warehouses | Check whether data is fresh and how full a warehouse is |
| Start a sync | Run a connection now |
| Write the fluid | Put tables on the map and define metrics, dimensions and filters, live at once |
| Load and add rows | Land tables of its own rows, or append to tables you have opened for intake |
| Define views and procedures | Build and schedule derived views on your compute |
| Run and commit SQL | One statement at a time, committed, with no undo |
| Manage search | Create and rebuild sanda search services |
| Email reports | Schedule report deliveries and send them |
An assistant can also look up how sanda works. The search_docs tool searches these docs, the same ones you are reading, and returns the matching sections with their links, so an assistant can answer "how do I connect a source?" from the page rather than from memory. It reads no data of yours, needs only fluid:read and costs nothing on the AI limit.
The full list is in scopes, and every tool, with its parameters, is in the MCP tool reference.
What an assistant cannot do
Nothing here widens what sanda can see. It changes who is holding the map.
- It reads only what you have modelled and accepted. Proposals waiting for review are not visible, and neither is a table that is not on the map.
- Questions go through a read-only role. Raw landed data, other workspaces and anything outside the accepted fluid are out of reach, whatever SQL an assistant writes. The permissions that write are the exception, and each says so in plain words on the consent screen.
- Answers are capped. A question returns at most 50 rows, and each statement has a timeout.
- A tool it may not use is not offered. It is absent from the tool list rather than present and refusing, so an assistant never tries what it cannot do.
- It never sees a credential. Connection lists and warehouse lists never include a password or connection string.
- Writes exist only behind a permission. A connection that was only granted questions cannot change anything.
Two ways to connect
| Sign in with OAuth | Hold an integration token | |
|---|---|---|
| For | A person connecting an assistant such as Claude or ChatGPT to their own workspace | A machine: Claude Code, the Claude API, an agent harness of your own |
| Set up by | Pressing Allow on sanda's consent screen | An owner or admin creating a token and pasting it into the client |
| Acts for | The person who approved it | The owner or admin who created it |
| Ends when | You disconnect it, or you leave the workspace | The token is revoked or expires, or its creator leaves the workspace |
If a client offers both, use OAuth: there is no secret to store. Step by step:
Editions
MCP and agents are included on every edition, and on a trial. The search tools need sanda search, which is included from Standard. The Excel and Power BI feed and its tokens work on every edition. See editions.
sanda search tools follow sanda search, which is also on Standard and Enterprise.
Watch what agents do
Open Intelligence · Agents in the console. Every member can see it. It answers the question the credential screen cannot: is it working?
- Harness lists four things that must be true before an agent can do anything: a healthy warehouse, definitions on the map, a live credential, and (optionally) text an agent can search. Each one that is not true links to the page that fixes it.
- Agents has one row per integration token or connected app, with what each may do in plain sentences, the permissions that go beyond asking questions marked, and when it was last used.
- Activity has four tabs. Sessions groups one credential's calls with no gap of 15 minutes or more, because MCP holds no session of its own. Calls is the live feed. Refused lists what sanda declined to run at all, such as an unknown tool or a missing permission. By tool shows which tools are leaned on and which keep answering no.
- Approvals, for owners and admins, holds the risky actions an agent asked for until a person decides.
A tool that answers no and a request sanda refuses are different things. An answer of no ran and explained itself in a sentence the assistant can act on ("those two tables fan out"). A refusal means sanda declined to run the tool: an unknown tool, a permission the credential does not hold, or a protocol mistake by the client. Refused is the tab to read when an assistant says it cannot see anything.
The activity feed shows that a call happened and how it went. It does not keep the rows that came back.
Every action is recorded and approvable
Every tool call is recorded with the credential that made it, the tool, how long it took and whether it answered no. Changes an agent makes go through the same handlers as the console's own buttons, with the same validation and the same audit record, so a metric an assistant defines is checked exactly as one you define yourself.
For the few actions that cannot be undone (committing SQL, dropping a view or a search service, emailing a report to an address outside your members' email domains), an owner or admin can require a person to approve first. The action waits, the owners and admins are emailed, and nothing runs until someone presses Approve and run. Approval is off by default. See permissions and approvals.
cherry is not MCP
cherry, sanda's own agent, lives in the console and is on every edition. It uses many of the same tools under your own role, with its own approval rules. See cherry.
Something unclear or out of date? Tell us, and we will fix the page.