MCP Server
Roles & Access
Which tools your role can see and call
The MeshMesh MCP server enforces your workspace role on every request. Your role comes from your workspace membership, resolved from the identity in your OAuth token.
Roles
Roles are ordered, least to most privileged:
viewer → member → admin → owner
What each role sees
- Any signed-in workspace user gets the agent, artifact, reference, connection, workbench, and identity tools, plus Library read (
library_search,collection_list). - Admins and owners additionally see the Library admin tools — the review queue, publishing and curation, and collection management.
Admin-only tools are hidden entirely: if your role can't use a tool, it does not appear in your client's tool list and cannot be called. See the Tool Reference for which tools are admin-only.