Manage MCP Trust¶
The Admin → MCP area provides the customer-facing controls for the SchemAlign deployment's MCP connection.
Connection & Health¶
Use Connection & Health to review whether the deployment is connected to SchemAlign MCP.
When connected, administrators can:
- test the current connection
- rotate deployment trust
- repair MCP trust when recovery is required
- disconnect the deployment
Test Connection¶
Use Test Connection when you want to confirm that the deployment's current MCP trust is valid.
Testing does not intentionally revoke user authorizations or replace deployment trust.
Rotate Trust¶
Use Rotate Trust for routine credential rotation.
Rotation replaces the deployment trust credential while keeping the deployment connected.
Use this as the normal maintenance action when the existing connection is healthy.
Repair MCP Trust¶
Use Repair MCP Trust when the deployment connection needs to be re-established rather than normally rotated.
Repair is a recovery action.
It:
- verifies control of the existing SchemAlign deployment
- establishes new deployment trust
- revokes the previous deployment credential
- revokes existing AI-client authorization state associated with the old trust
- keeps the SchemAlign deployment connected with the new trust
Users must reconnect after repair
Repair intentionally invalidates existing AI-client authorizations. After a successful repair, users must reconnect SchemAlign in ChatGPT and complete authorization again.
Repair is designed so a customer administrator can recover the deployment without signing in to a separate MCP infrastructure server or requesting an operator-issued enrollment token.
Disconnect¶
Use Disconnect when the deployment should no longer participate in SchemAlign MCP.
Disconnect removes the active deployment trust and causes existing MCP access to stop working.
Reconnect the deployment from Connection & Health when MCP should be enabled again.
User authorization revocation¶
Deployment trust and user authorization are separate controls.
If only one user's ChatGPT access should be removed, revoke that user's AI-client authorization rather than disconnecting the entire SchemAlign deployment.
If organization access should change while the user's ChatGPT connection remains active, update the organization's MCP policy or the user's normal SchemAlign access.
See Access & Permissions for the authorization model.
Choosing the right action¶
| Goal | Recommended action |
|---|---|
| Confirm the connection is healthy | Test Connection |
| Perform routine trust maintenance | Rotate Trust |
| Recover a broken or inconsistent trust relationship | Repair MCP Trust |
| Remove one user's AI authorization | Revoke that user authorization |
| Remove one organization's MCP visibility | Change organization MCP access |
| Stop MCP for the deployment | Disconnect |