Skip to content

Integrations ​

Integrations connect agents to the systems your company already uses: Slack, Google Drive, Docs, Sheets, Calendar and Gmail, Notion, Jira and Confluence, GitHub, GitLab, Grafana — and anything else that speaks MCP.

They are set up per owner, in Settings → Integrations, by its owners and admins.

Whose account the agent uses ​

This is the decision that matters, and it is made per integration:

ModeHow it worksUse it when
Shared accountOne token, set by an admin. Every agent acts as that account.A service account with deliberately narrow access, e.g. a read-only Grafana viewer
Each person's tokenEveryone pastes their own in Account → ConnectionsThe system issues personal tokens, e.g. a GitHub PAT
Each person's account (sign-in)Everyone signs in once and the connection is keptSlack, Google, Notion, Atlassian, GitLab

With the per-person modes, a call uses the connection of whoever is asking — or, for a scheduled task, of whoever owns the task. An agent therefore never sees more than the person using it already could. Without a connection, the tool politely says so.

With a shared account, everyone who can use the agent effectively has that account's access. Choose what it can reach accordingly.

Which tools an agent gets ​

A server offers many tools; an agent gets only the ones an editor ticks.

Read-only tools (ones the server marks as such) are the sensible default and can be added in one go. Everything else counts as a write and has to be ticked on purpose, with a warning: those are the calls that post the message, close the issue, change the document.

The selection is part of the agent's published version, like everything else.

Tokens and safety ​

  • Tokens and sign-ins are encrypted at rest, tied to the row they belong to. They are never shown back to you, and never given to a model.
  • A connection that stops working is marked as needing reconnection rather than failing silently.
  • Results coming back from an integration are data, not instructions. A ticket description or a chat message can contain text aimed at your agent; agents are told as much, and write tools being opt-in is the second line of defence.
  • Every call is in the audit log.

Anything else ​

Custom MCP server connects any server that speaks MCP over HTTP. If it supports the standard sign-in flow, CrewHall registers itself; otherwise an admin enters the client details. Servers that only run as a local process are not supported yet.

CrewHall