Security and governance for AI assistant connections

Robin's MCP server lets employees use Robin from AI assistants such as Claude and ChatGPT. Each action runs as the signed-in user and is limited by that user's Robin permissions. Robin receives the requested action, its inputs and the user's identity. It does not receive the user's prompt or conversation.

Use these details in your IT, security and privacy review of AI assistant connections. The controls apply to third-party AI assistants that connect through Robin's MCP server. They do not affect Robin's own apps. To set up a connection, see Using Robin in your AI Assistant.

Administrators can turn off AI assistant connections for their organization. Organizations with custom roles can also limit which users can connect. Robin does not give administrators an audit log of connector activity.

How an AI assistant connects to Robin

An AI assistant reaches Robin through Robin's MCP server at https://mcp.robinpowered.com/mcp. A connection works like this:

  1. The user adds Robin to their AI assistant and selects Connect.
  2. The assistant sends the user to Robin's sign-in page. The user signs in with their Robin credentials or your organization's SSO.
  3. Before Robin shows the consent screen, it checks the organization setting and the user's AI assistants permission. Both must allow the connection. If either does not, the user sees an explanation and Robin issues no token.
  4. The user approves the consent screen. This is the user's consent, not administrator approval.
  5. Robin issues an access token and a refresh token. The access token expires after 1 hour. The refresh token lets the assistant get a new access token without another sign-in. Robin checks both controls again at every refresh.
  6. The user asks for something, and the assistant calls a Robin action, such as listing available desks. The action runs as the user and is limited by the user's Robin permissions.

Robin receives the action requested, its inputs (for example, a floor and a date) and the user's identity. Action inputs can contain information from the user's request. Robin does not receive the user's prompt, the conversation, or what the assistant does with the results.

After Robin returns a result, the AI provider processes it under the terms of the user's AI account. See Data processing, retention and training.

Data an AI assistant can access

An assistant can use only the actions that Robin's MCP server exposes. The signed-in user's Robin permissions limit each action. Depending on those permissions, an assistant can access this data:

Data What it can return Changes it can make
The user's own desk reservations Desk, floor, building, time and check-in state Book, extend, shorten or cancel
Other people's desk reservations Who is booked where and when. Private (Just me) reservations are not included. With delegate permission, book or cancel for someone else
Desk availability Free and booked desks for a time window, and booking rules None
Buildings and floor plans Buildings, floors, desks, desk types, neighborhoods and building hours Only through scenario-planning drafts
People directory Name, email, department, job title, manager and reporting line None
Department headcount Number of people in each department None
Scenario planning and stack plans Drafts, desk assignments in drafts and saved stack plans Needs planning permission. Users with publish rights can publish a draft to the live floor plan. When the assistant invites collaborators, Robin sends them an email.
Workplace analytics For one building: commonly booked rooms by type, rooms under capacity, desk check-in days by individual, and average desks reserved by team. Needs planning access to the building. None

Robin does not expose a live presence or occupancy signal through the connector. But reservations and desk check-in history are available, and both can show when someone was in the office. Treat them as attendance data in your privacy assessment.

A change made through an assistant is an ordinary change by that user. It shows wherever it normally shows in Robin. The assistant and its settings decide whether the assistant asks the user to approve an action first. Robin does not control this.

For the full list of actions, see Robin MCP server and available actions.

Control who can connect an AI assistant

AI assistant connections have 2 controls. Both must allow a connection. Robin checks them at sign-in and at every hourly token refresh.

Control Where What it does Availability
Allow MCP connections (organization setting) Integrations > Manage MCP Access When it is off, no one in the organization can connect, including Admins and Owners. Existing connections stop working within 1 hour. It is on by default. Every organization
AI assistants (role permission) Roles > Features > AI assistants Decides which users can connect. The Member role has it by default. Organizations with custom roles

If your plan does not include custom roles, the organization setting turns connections on or off for everyone.

The AI assistants permission decides whether a user can connect. The user's other Robin permissions decide what the connection can read or change.

Restrict AI assistant connections to specific users

To let only approved users connect, give the permission through a custom role:

  1. Remove the AI assistants permission from the Member role.
  2. Add the permission to a custom role for approved users.
  3. Assign that role to the users who need to connect.

A user can connect only if one of their roles has the permission. After step 1, check the roles your administrators hold. If your administrators need to connect, make sure one of their roles still has the permission.

Revoke AI assistant access

Turn off the organization setting, or remove the permission from a user, to stop their connection within 1 hour. The current access token works until it expires, but Robin does not issue a new one. Robin does not revoke individual tokens. Access ends when a check fails.

If Robin cannot verify access when a token is due for refresh, it does not issue a new token. The same applies to new sign-ins. When you remove a user from your Robin organization, their connection also ends within 1 hour, because Robin checks organization membership before it issues each new token.

Users can also disconnect Robin in their AI assistant's connector settings. Ending access does not remove data that Robin already returned to the AI provider.

Governance limits

The controls have these limits:

  • Robin cannot tell personal AI accounts from organization-managed ones. Robin cannot require a user to connect through your approved enterprise AI account.
  • There is no allowlist for each assistant. You cannot allow one assistant and block another.
  • There is no administrator approval workflow for each connection request.
  • The controls apply to the whole organization, not to individual buildings or locations.

Use your acceptable-use policy and your AI provider's administrative controls to govern which accounts and providers employees can use. Robin cannot enforce that policy.

Monitor and audit connector activity

Robin does not give administrators a log of AI assistant connections or activity. A change made through an assistant, such as a desk booking, shows as an ordinary record by that user. These records are not a connector audit trail.

Robin keeps internal operational logs of connector calls. Each log records the organization, the action, whether it succeeded and how long it took. These logs, and the traces Robin uses to monitor the service, do not include the user's identity.

Robin does not record the inputs sent to actions or the data they return. Customers cannot see the internal logs.

Robin does not receive prompts or conversations. Your AI provider and plan decide whether you can see them. Check the provider's audit and compliance documentation.

Data processing, retention and training

Robin processes each request and returns Robin data to the assistant. The AI provider processes those results, together with the user's prompts and conversation, under the terms of that AI account.

Topic Robin AI provider
Data handled Your Robin data and connector requests Results Robin returns, plus the user's prompts and conversation
Model training Robin does not use connector requests, returned data or connector logs to train models Check the provider's current terms for that account
Retention Internal connector call logs are searchable for 30 days and archived for up to 365 days Check the provider's current terms for that account
Location Robin's US infrastructure Check the provider's current data-location and transfer terms for that account

Personal and enterprise AI accounts

For an organization-managed AI account, confirm that your agreement with the provider covers Robin data and this integration. Check processing, retention, model training, data location and international transfers.

A personal AI account usually falls under the provider's consumer terms, not your organization's agreement. Robin cannot control which account a user chooses. If that is not acceptable, turn off the organization setting or restrict the AI assistants permission.

For Anthropic, see the Anthropic Privacy Center. Check the same pages for any other provider you approve.

Hosting and regional availability

The MCP server runs on Robin's US infrastructure. Organizations hosted on Robin's EU infrastructure cannot connect AI assistants. Availability depends on where your Robin organization is hosted, not where your users are.

UK GDPR and EU GDPR

See Robin's Privacy Policy for Robin's privacy practices. To request data protection and data transfer agreements, contact gdpr@robinpowered.com.

Before you allow AI assistant connections, confirm that 2 agreements cover the Robin data available through the connector, the intended use and any international transfers: your agreement with Robin, and the agreement for the AI account. A user's consent to connect does not replace that review.

Checklist for security and privacy reviews

Use this checklist in your review:

  • Decide whether AI assistant connections stay on during your review. If not, turn off the organization setting.
  • Confirm that your Robin organization is hosted on US infrastructure, and review the transfer arrangements that apply.
  • Review directory, reporting-line, reservation, check-in and analytics data against your privacy assessment, including data about other employees.
  • Decide which users can connect. With custom roles, give the AI assistants permission only to approved users, and check your administrators' roles.
  • List approved AI providers and account plans, and cover personal accounts in your acceptable-use policy.
  • Confirm the AI provider's retention, training, data location, audit and transfer terms for the approved service.
  • Decide whether your organization can accept having no administrator log of connector activity.
  • Remind users that assistants can change Robin data, including desk bookings and, with publish rights, live floor plans.

Related articles

Articles in this section

Was this article helpful?
0 out of 0 found this helpful
Share