Articles in this section

Create and manage capability sets on MCP servers

Capability sets let you group related capabilities on an MCP server so you can assign them together. Instead of selecting individual capabilities each time you grant access, create a capability set once and reuse it when assigning access to groups or end users. 

For example, on a NetSuite MCP server you might create an Order Management capability set for sales order operations and a Reporting capability set for read-only reporting tools. You can then assign the appropriate set based on each user's responsibilities.

Note: Capability sets are optional. To grant access to every capability on an MCP server, select All capabilities (or Select all) when assigning access.

Before you begin

  • You must have the administrator access level
  • Your account must be multi-environment. Capability sets aren't available on legacy sandbox-only accounts
  • The MCP server must already exist
  • The MCP server must have one or more capabilities available

Create a capability set

  1. Go to AI studioMCP server → server → Access tab.
  2. In the Capability sets section, Click + Create capability set. If you have previously created a capability set, click + Create capability set in the upper right side of the page.

    create capability set.png

  3. Enter a Name.
  4. Enter an optional description.
  5. In the Capabilities tab, click + Add capabilities to select Tools and APIs. Click Save to view the selected capabilities in the set.
  6. In the Access tab, you have options to assign users and groups. See Create and manage end-user groups and Invite and manage end users.

    capabilities_access.png

  7. Click Save & close. The capability set is now available when assigning access to groups and end users.

Assign a capability set

In August, capability sets can only be assigned from the capability set's own Access tab and not from the group or end user side.

  1. Go to AI studioMCP servers → server → Access tab → Capability sets, and open the set.
  2. In the Access tab, use the Users and Groups sub-tabs to assign the set to specific end users or groups.
  3. Click Save & close

The account admin screens for groups and end users don't offer a capability set picker.

Manage capability set

To see all MCP servers in your account, Go to the AI studioMCP servers → server → Access tab → Capability set. It displays the following details:

capability set details.png

  1. Name/description - Displays the name and description you gave your capability set
  2. Assigned to: Displays the end users and groups currently assigned to this capability set. End users are listed first, followed by groups. If the capability set isn't assigned, an em dash (—) is displayed.
  3. Capabilities: Displays the number of capabilities added
  4. Actions: You can perform the following action for each capability set:
    • Edit: Click to open a capability set and update its name, description, or capabilities and select Save

      Note: Changes automatically apply everywhere the capability set is assigned. Users gain or lose capabilities based on the updated definition

    • Clone: Copies the set into a new draft named "Clone - {name}" and opens the create drawer. Nothing is saved until you save the clone

    • Delete: Click Delete and confirm the deletion. Note: Deleting a capability set removes the set itself, but doesn't revoke access, each assignee's reference to the set is replaced with direct selections for the capabilities the set contained at the time of deletion, so nothing is lost. Those kept capabilities show as Direct afterward

How capability sets work

Capability sets are scoped to a single MCP server. A capability set can include any combination of the server's capabilities, and the same capability can belong to multiple capability sets. 

When assigning access, you can combine capability sets with individual capability selections. Users receive the combined permissions from all selected capability sets and any individually selected capabilities. 

If you need to grant access to every capability on an MCP server, use All capabilities during assignment instead of creating a capability set for that purpose.