AI Assistant Access and Security
What your AI assistant can see, and how to disconnect it
Written By David
Last updated About 15 hours ago
Your AI assistant sees the same Cromojo data you do, and nothing more. You can cut off its access at any time.
What the assistant can see
Workspace owners and Members get every website in the workspace.
Guests only get the websites they've been given access to.
Nobody can reach another customer's data, even by naming their domain.
The assistant can only read. It can't change settings, submit pages for indexing or edit anything in Cromojo.
Your AI provider receives the answers the assistant asks for, so their privacy terms apply to your conversation.
Disconnect an assistant
In Account Settings > MCP:
Under Connected apps, click Disconnect next to an assistant you signed in with. It loses access right away.
Under Personal access tokens, revoke a token you no longer use. It stops working right away.
Pause every assistant at once
Switch MCP access off in Account Settings > MCP. Every connected assistant and token stops working, but nothing is deleted. Switch it back on and they work again without reconnecting.
Keep access tokens safe
Treat a token like a password: anyone who has it can read your Cromojo data.
Choose an expiry date when you create it, unless you really need one that never expires.
Give each assistant its own token, so you can revoke one without affecting the others.
If a token may have been shared by mistake, revoke it and create a new one.
Troubleshooting
I don't see the MCP tab. MCP is being released gradually. Ask the team if you'd like early access.
"MCP access is disabled for this account." Switch MCP access back on in Account Settings > MCP.
"Site not found". Ask the assistant to list your websites first, then use the name exactly as listed. You may not have access to that website, or it may be switched off.
The sign-in page doesn't open. Use an access token instead.
It stopped working. Your token may have expired, or the assistant was disconnected. Create a new token or connect again.
Related articles
Still need help? Ask the team