Personal vs shared
Opt-in (default off)
When a governor shares an MCP, it does not appear in other members’ chat until each person opts in (MCP Plugins or the Connectors modal). Preferences are per user and default to off. Tool chips are also per user: turning a capability off for you never changes a teammate’s selection.Who can do what
- Create a personal MCP — members with permission to add Custom MCP servers.
- Share, unshare, or set a workspace static credential — governance permission (
mcp:plugins:manage/ workspace MCP governance). - Delete a shared MCP — governance.
- Connect OAuth — every user who wants to use that server, including on a shared MCP.
Tess never reuses someone else’s OAuth token. If a shared OAuth MCP has no connected token for you, Tess hides it from tool discovery instead of calling it unauthenticated.
Fail-closed credentials
If Tess has no usable credential for you (expired OAuth, missing static token, failed connection), the server is treated as disconnected. It is not injected into the agent with empty auth.Related
- Custom MCP — add and connect a server
- MCP best practices

