The Chili Piper MCP currently exposes both read and write capabilities under a single API key configuration. Admins who want to give their teams access to pull data, analytics, and reporting via AI tools have no way to restrict those connections to read-only access, meaning any MCP connection also carries the risk of write actions being executed against live configuration.
Admins should be able to scope MCP access at the permission level, specifically separating read operations (pulling analytics, availability data, user info) from write operations (modifying users, duplicating assets, changing configuration), so teams can safely enable AI-powered reporting workflows without exposing administrative capabilities to unauthorized users or untested AI agents.
This is a prerequisite for broader MCP adoption in organizations with strict change management policies, where ops teams want to enable AI access incrementally rather than all-or-nothing.
Created by Taylor Jennings
·