Incoming messages tell the application what the customer wants. They should not redefine which projects, conversations or external tools the worker is allowed to access.
Give the worker a narrow identity
Use a documented project or account scope that matches the job. A worker answering one business line usually has no reason to read unrelated workspaces or change the event destination.
Miss Blue documents project keys and separately scoped user sign-ins. Its CLI reference also states that local logout currently differs from server-side revocation of a saved sign-in.
Bind context to the conversation
Resolve the incoming event to a trusted conversation identifier before retrieving private context. Avoid selecting a thread because the message text asks for a person’s name or another account.
The application should enforce that mapping outside the model. A plausible instruction in a customer message remains untrusted task content.
Review high-impact tools separately
Sending, deleting local data and changing webhooks have different consequences. Expose only the actions the workflow actually needs and enforce approval where required.
MCP makes tools available to the client. It does not establish that the client will apply your business’s authorization or privacy rules.
Plan for a credential change
Know how to rotate a key and stop the worker without losing accepted incoming messages. Keep the recovery job state independent from the secret itself.
Check revocation and role behavior with the provider before rollout. Our reviews link current documentation, but do not constitute a security audit of any platform.