Use case · By risk
Record why an agent needs an external host
For teams reviewing access to external services.
An agent needs a site that has not been reviewed. The useful question is what data will go there and why the task needs it. Capture the access request as a Work task. Name the host, the intended use and the owner, then add the review outcome to the comments.
Network off the allowlist
Review access to an external service
- 1
Next action
Document the destination and data involved
- 2
Context
Host and purpose
- 3
Evidence
Data to be sent or received, without secrets
What to put in the task
- Assign the task to the person responsible for the next action.
- Add evidence links and explain what they show in a comment.
- Update the task when the work changes so the next reader has the current state.
Before you rely on it
Command interception depends on your client's hooks or proxy; see the setup guide for Claude Code, Codex, Cursor and other MCP clients.
- A Work task is not a network allowlist. Enforce outbound access in your network or client controls; a device report does not prove that all traffic is intercepted.
- Work must be enabled for the selected account, and you need permission to read or change the task. Security access and device setup are separate.
Related use cases and clients
By riskMCP servers off the org listThe integration has a documented purpose and an accountable reviewer.By riskSecrets and env filesThe next person can see which configuration changed and who handled it without asking for the secret in chat.By clientAny MCP clientSetup requirements for any MCP client.
All use cases →