Before you start
You need an MSPortal account, access to Settings > MCP Server, and MCP Server write permission to connect or revoke clients. Read-only settings access lets you inspect the page but does not authorize a connection. Your MSP administers Company-user permissions. Choose a client that supports remote Streamable HTTP MCP and browser OAuth authentication. A generic MCP setting or local-server support alone is not enough. Your client subscription and organization policies can also affect availability. The connection uses browser sign-in and OAuth consent rather than a portal API key. Data returned by tools goes to the external AI client you connect, under that service’s handling and your organization’s policies. Connect only the areas you intend to use.Connect your client
Copy the correct server URL
Choose the client setup card
Add the remote server in the client
Authenticate and review consent
Verify a real connection

MSP setup dialog; no client authorization submitted.
Codex CLI
Replace the quoted placeholder with the Server URL copied from MSPortal:[mcp_servers.msportal] in Codex configuration, with url set to the copied URL. See official OpenAI MCP instructions for client configuration and tool controls.
Other clients
Use the matching in-app card for Claude Code, Claude Desktop/Web, Cursor, GitHub Copilot in VS Code, Gemini CLI, Windsurf or other compatible clients. Configuration formats differ: do not paste another client’s JSON or CLI syntax unchanged. Client releases can change menus; use that client’s current documentation when its interface differs from the card.What an assistant can do
Tools cover tickets, devices, reporting, Planner, goals, budgets, meetings, compliance, projects, financial data, cloud services, security, backup, surveys, training, onboarding and other supported areas. Read the MCP Tools Reference for exact capabilities and action behavior. The available set depends on deployed tools, consent scopes, your role, company access, provider availability and client-side selection. A Company identity does not inherit MSP-only tools by granting broader scopes. List results can be paginated or truncated; a small response is not proof of a complete portfolio search.A smaller tool catalog
The consolidated catalog groups related operations into 93 public tools, covering the same 260 existing operations. Read tools use names such asquery_planner; changes use names such as manage_planner, with a separate action for creating, editing or archiving an item. The assistant uses the input schema to choose the action and its arguments.
The full catalog fits below a 128-tool client budget without deselecting feature areas. Your consent screen counts the grouped tools available to your account. Scopes, role permissions and company access still apply to each action, and other connected servers may contribute additional tools to your client’s total. The exact catalog depends on the deployed server version.
Existing connections
Existing tool names remain callable with their original arguments and response shapes, including the two compatibility aliases. Pending confirmations retain their original operation identity and expiry. You do not need to change the server URL or grant broader access just because the catalog is consolidated. When your client refreshes its tool list, it sees the grouped names. Update any tool-name allowlist when adopting those names. Custom clients that require old names to appear intools/list must update their discovery logic; preserving old calls does not preserve the old discovery response. See grouped calls and legacy compatibility.
A useful first request is: “Use read tools to identify the company I name and summarize the available evidence. Do not change records or send messages.” Check cited records, dates and gaps before requesting follow-up work.
Confirmation before changes
Most portal mutations use a proposal/confirmation flow:- Request the proposed change and inspect the returned preview, company, records and effects.
- Approve that proposal only when it matches your intent.
- The client confirms the staged proposal before it expires, normally within ten minutes.
- Verify the resulting record or background operation. An accepted job request is not proof of completed provider delivery.
Ron: the AI vCIO skill
The optional Ron skill provides instructions for client briefings, risk reviews, QBR preparation and planning. It does not establish an MCP connection or grant permissions, and cannot guarantee that every client follows its instructions. The published package has a SKILL.md, references/playbooks.md and references/tool-map.md. Review and install the files together using your client’s supported skill or instruction mechanism. Preserve their relative paths. Do not blindly append downloaded content to an existing project instruction file. Use the published Ron skill, playbooks and tool map, or the matching paths on your regional portal. Keep your chosen instructions consistent with the actual tool confirmation and immediate-action behavior above. An assistant answering without tool calls does not prove the skill failed to load. Check server connectivity, enabled tools and the actual calls made; ask for an evidence-backed answer.Connected clients and revocation
Connected clients lists the applications authorized by your current user, with their names, first-party/external labels, last-authorized time, session count and scopes. It is not a tenant-wide inventory of every employee’s clients. Session counts describe active refresh-token sessions, not a live count of open browser tabs. Select Revoke for the intended client and confirm to revoke your grant and refresh sessions. There is no separate page Save. Already-issued access tokens can remain valid until expiry, up to about 15 minutes. Removing the user’s MCP Server write permission blocks subsequent MCP requests through the permission check. Ask the MSP administrator to make role changes when required. Revocation does not erase data already returned to the external client, undo completed actions or remove the local server configuration. Reconnection requires authentication and consent again.Troubleshooting
Frequently asked questions
Can read-only MCP settings users connect new clients?
Can read-only MCP settings users connect new clients?
Do broader OAuth scopes override my portal permissions?
Do broader OAuth scopes override my portal permissions?
Will consolidation break calls using the old tool names?
Will consolidation break calls using the old tool names?
Does a proposal mean a record was created?
Does a proposal mean a record was created?
Can I change a proposal by changing the confirmation arguments?
Can I change a proposal by changing the confirmation arguments?
Does every action wait for a second confirmation call?
Does every action wait for a second confirmation call?
Will the assistant automatically report missing features to MSPortal?
Will the assistant automatically report missing features to MSPortal?
Does Revoke immediately invalidate every existing access token?
Does Revoke immediately invalidate every existing access token?
Does Revoke erase information already sent to the client?
Does Revoke erase information already sent to the client?
Does the Ron skill replace authentication or permissions?
Does the Ron skill replace authentication or permissions?