Who Can Use AI
Access to Holistics AI depends on both your role and what your admin grants you.
Permission
| Role | Access to AI |
|---|---|
| Viewer | Not available |
| Explorer | Available, if granted by an admin |
| Analyst | Available, if granted by an admin |
| Admin | Always available, with In-app & MCP access |
We're considering AI access for Viewers.
Control access for your users
Splitting AI access into In-app only and In-app & MCP is launching soon. Until then, granting a user or group AI access grants both together.
Admins can control who can use Holistics AI (either in-app only or also via MCP). This helps you:
- Roll out AI gradually, enabling it for selected teams first.
- Make sure only users you trust to use an ungoverned AI client responsibly get MCP access.
Where to manage it
Go to Organization settings → AI settings → User access. This controls access per user. To turn AI off entirely, or for specific features, see Enable AI.
Access levels
When granting AI access to a user or group, you also choose whether that access includes the MCP server:
- In-app only: the user can use AI inside Holistics, but cannot connect to Holistics through MCP-compatible tools like Claude.
- In-app & MCP: the user can also connect their own AI client (e.g. Claude) directly to Holistics via MCP.
In-app only is the default when you grant access to a user or group. You choose In-app & MCP explicitly for users you trust to use an ungoverned AI client responsibly.
Effective access
If a user's access comes from multiple sources (a direct grant and one or more groups), their effective access is the broadest of all of them. For example, if a user is granted In-app only directly but belongs to a group with In-app & MCP, they get In-app & MCP.
Admins always have In-app & MCP access, and this cannot be changed.