Skip to content

Is it possible to limit accessible orgs? #122

Answered by cristiand391
jwalke asked this question in Q&A
Discussion options

You must be logged in to vote

Ideally, this could be enforced at the enterprise/policy level so that an employee couldn't intentionally or unintentionally point their MCP server to prod

There's no settings in org UI for these kinds of local servers so this is unlikely to happen.

Is there a Salesforce permission that determines this access? Assume that the user requires admin access to prod though, could a permission be set to ensure that their coding agent doesn't have admin access to prod?

You could create a connected app for CLI auth and not give it the "API request" scope but it would also block CLI operations.
Not sure how we could use permsets to block this scenario, on the org side these are usually "API per…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@jwalke
Comment options

@cristiand391
Comment options

Answer selected by jwalke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants