An MCP connection is an authorization that stays active after you close your assistant. This article explains how long it lasts, what happens to it when someone is deactivated or leaves a workspace, and where an admin can review everything that reaches the company.
If you have not connected an assistant yet, start with How to connect your AI Assistant (MCP). For the step by step of each client, see How to set up MCP in Claude, ChatGPT, Codex and Copilot.
Who a connection belongs to
An authorization always belongs to a person, not to the company. The assistant acts on behalf of whoever authorized it and never gets more permissions than that person already has in each workspace.
This works both ways: what the person cannot see, the assistant cannot see either, and when their permissions change, the assistant's reach changes with them on the next call.
What happens when someone is deactivated or leaves
Coodesh checks the account and its permissions on every request the assistant makes, so there is no waiting period:
Deactivated account: every connection that person made stops working, in every workspace.
Person removed from the workspace: the assistant loses access to that workspace. If it was also authorized in other companies, it keeps working only there.
Permission removed: the assistant stops seeing whatever the person can no longer see.
In other words, deactivating the account of someone who left already cuts their assistant off. Even so, reviewing the workspace connections during offboarding is worth it, so you know what was connected.
How long an authorization lasts
An authorization is valid for up to 90 days. After that the assistant asks for a new one and the person has to sign in to Coodesh and approve it again. Using the assistant every day does not extend this period.
The connections card shows the date each authorization expires. Reauthorizing is the same flow as the first connection and takes a few seconds.
Where an admin reviews the workspace connections
Under Settings > Security, the Assistants connected to this workspace card lists every assistant that reaches the company, from any member. The card is available to workspace admins.
Each row shows:
the assistant and the person who authorized it;
the last use and the date the authorization expires;
the permissions granted, split between Read and Change;
warnings when the account is deactivated, when the person is no longer part of the workspace, or when the same assistant also reaches other workspaces.
How to disconnect an assistant
On the workspace card:
Find the assistant's row.
Click Disconnect.
Access to that workspace is cut immediately, including sessions the assistant already had open.
Each person can also review and disconnect their own connections under My account > Security, where their assistant's recent activity is shown as well.
Frequently asked questions
I deactivated the person's account. Do I also need to disconnect their assistants?
Not to cut off access, which already ends with the deactivation. Disconnecting keeps the list clean and records the review.
Does disconnecting in one workspace affect the others?
The card warns you when the same assistant reaches other workspaces. In those cases, depending on how the authorization was granted, it may need to be authorized again to keep working in the remaining workspaces.
Is the person notified when I disconnect?
We do not send a notification. The connection disappears from their card under My account > Security and the assistant asks for a new authorization on its next attempt.
Can I see what the assistant did?
Each person sees the recent activity of their own connections under My account > Security: the queries the assistant made, the workspace for each one, and the reason whenever something was denied. The workspace activity log keeps the authorizations that were granted and revoked.

