Enabling external AI applications
Staff can connect their own AI application (Claude, ChatGPT, Cursor …) to their roleALPHA account. Whether your tenant permits this at all is your decision.
You will find the switch under Settings → AI settings, card External AI applications.
What you are permitting
Section titled “What you are permitting”A connected application acts with the full permissions of the person who connects it — reading and writing. It never sees more than that person would see in roleALPHA: the tenant boundary, visibility levels and role permissions apply unchanged.
Which areas an application can see at all is controlled via the same data release you already use to determine what rALPH may access (AI settings). An area that has not been released is invisible to a connected application too.
There is a second, independent limit: a service your organisation has not subscribed to is not offered at all — neither to rALPH nor to a connected application. The data release and the subscription are two separate decisions, and the release stays unchanged when a service is removed; only what appears in both is offered.
The switch is independent of whether you have enabled rALPH: with MCP access it is not roleALPHA that calls a language model, but the user’s application that reads the data.
Who is connected
Section titled “Who is connected”Below the switch you see all connections of your tenant: which person, which application, since when, when last used. Each can be disconnected individually.
The name of the application comes from its own registration and is not verified. It is suitable for orientation, not as proof.
Switching off
Section titled “Switching off”Switching off terminates all existing connections of this tenant — including sessions in progress. This is deliberate: otherwise the list would show connections that no longer work, and on switching back on they would silently come alive again without anyone having consented afresh.
Connections are also terminated automatically when a person leaves the tenant, their account is deactivated, or their sign-in methods are reset.
What is logged
Section titled “What is logged”Every call made by a connected application appears in the usage analysis with the marker mcp, broken down by application. Calls that change something additionally create an entry in the change history with tenant, person, tool and application.
Of the arguments passed in, that entry keeps only keys and shape, never the values: First name and “text, 4 characters” instead of Anna. What stays readable are identifiers, numbers, yes/no and those choice values the tool itself declares as a fixed set. A failed execution is likewise reduced to an error type (such as “service unreachable”, “validation failed”) — the original message from a data node could quote a rejected field value.
Data protection
Section titled “Data protection”Connecting is a new processing activity and is described in the privacy policy (section C.5). Important for your assessment: if the connected application sends content to an AI provider, this happens outside the platform and under your organisation’s contract with that provider. roleALPHA is not involved and is in this respect neither controller nor processor. Selecting permissible applications, and assessing whether transmission to them is allowed, is up to you.