Integrations
Integrations connect agents to the systems your company already uses: Slack, Google Drive, Docs, Sheets, Calendar and Gmail, Notion, Jira and Confluence, GitHub, GitLab, Grafana — and anything else that speaks MCP.
They are set up per owner, in Settings → Integrations, by its owners and admins.
Whose account the agent uses
This is the decision that matters, and it is made per integration:
| Mode | How it works | Use it when |
|---|---|---|
| Shared account | One token, set by an admin. Every agent acts as that account. | A service account with deliberately narrow access, e.g. a read-only Grafana viewer |
| Each person's token | Everyone pastes their own in Account → Connections | The system issues personal tokens, e.g. a GitHub PAT |
| Each person's account (sign-in) | Everyone signs in once and the connection is kept | Slack, Google, Notion, Atlassian, GitLab |
With the per-person modes, a call uses the connection of whoever is asking — or, for a scheduled task, of whoever owns the task. An agent therefore never sees more than the person using it already could. Without a connection, the tool politely says so.
With a shared account, everyone who can use the agent effectively has that account's access. Choose what it can reach accordingly.
Which tools an agent gets
A server offers many tools; an agent gets only the ones an editor ticks.
Read-only tools (ones the server marks as such) are the sensible default and can be added in one go. Everything else counts as a write and has to be ticked on purpose, with a warning: those are the calls that post the message, close the issue, change the document.
The selection is part of the agent's published version, like everything else.
Tokens and safety
- Tokens and sign-ins are encrypted at rest, tied to the row they belong to. They are never shown back to you, and never given to a model.
- A connection that stops working is marked as needing reconnection rather than failing silently.
- Results coming back from an integration are data, not instructions. A ticket description or a chat message can contain text aimed at your agent; agents are told as much, and write tools being opt-in is the second line of defence.
- Every call is in the audit log.
Anything else
Custom MCP server connects any server that speaks MCP over HTTP. If it supports the standard sign-in flow, CrewHall registers itself; otherwise an admin enters the client details. Servers that only run as a local process are not supported yet.
