---
title: PlumoAI MCP Security Best Practices — PlumoAI Developer Guide
description: How to keep your PlumoAI workspace and data safe when connecting AI tools over MCP.
url: https://plumoai.com/developer-page/guides/plumoai-mcp/security
---

# Security Best Practices

Follow these guidelines to ensure secure usage of PlumoAI MCP

### Security Guidelines

#### 1\. Review permissions carefully

When connecting PlumoAI MCP, review the permissions requested by your AI tool. Only grant access to the workspaces and data that the tool needs to function.

#### 2\. Use workspace-specific connections

Connect MCP to specific workspaces rather than granting access to all workspaces. This limits the scope of what AI tools can access.

#### 3\. Monitor AI tool activity

Regularly review what actions AI tools are taking in your workspace. Check the activity log to see what pages are being created, modified, or accessed.

#### 4\. Revoke access when needed

If you no longer need an AI tool connected, or if you notice suspicious activity, revoke the connection immediately from your PlumoAI settings.

#### 5\. Use read-only access when possible

For tools that only need to read data, configure read-only access to prevent accidental modifications to your workspace.

#### 6\. Review AI-generated content

Always review content created or modified by AI tools before it's published or shared. AI tools can make mistakes, so human review is essential.

Important Security Reminders

- Never share your MCP connection credentials with others
- Be cautious when AI tools request access to sensitive or confidential data
- Regularly audit which AI tools have access to your workspace
- Use strong authentication methods for your PlumoAI account
