What an AI agent connected over MCP can (and can't) touch

Published on September 16, 2026

Every CMP in this segment is adding MCP this year. The question almost none of them answer in their marketing is what that agent can actually do once connected: what it reads, what it can change, and what stays out of reach by design.

MCP has become the box every CMP wants to check this year. CookieYes shipped it first in this segment. Cookiebot has its "MCP Manager." OneTrust mentions it in their developer portal. Ketch describes its APIs as "MCP-style" on their site. Before long, having an MCP connector will stop being a differentiator and become the expected baseline.

The question that actually matters isn't whether a CMP has MCP. It's what that connector can touch once Claude, or any other agent, is connected to your organization. That question almost never gets answered in marketing, because the answer usually lives in a technical document nobody links from the landing page.

First: which organization it's bound to

A Tripticonsent MCP access token is cryptographically signed for a single organization: the one you choose on the authorization screen. A call against any other organization gets a 403, no exceptions, even if the same Claude account also belongs to that second organization. This isn't an application-level check you could bypass with a different parameter. The token itself is worthless outside that organization.

Second: which permissions exist, not which ones are hidden

Every admin operation requires a specific permission, like sites:write or cookies:read. A permission not granted on the authorization screen isn't hidden in the UI: it's literally unreachable, because the server rejects it before the request ever reaches the controller. That distinction matters. A "hidden" surface can be exposed by a UI bug. A surface the server never exposes can't be.

Third: what stays out no matter what

  • No permission grants access to a subject's real identifier in plaintext. vault:read lets you search and see consent state, never decrypt the underlying identifier or export a full data dump.
  • No permission reaches LIVE API keys, existing key secrets, identity secrets, SSO or MFA configuration, team members, or billing. The only key access is creating and listing TEST-mode keys for development (api-keys:*). The rest sits entirely outside the MCP permission model, no exceptions.
  • Every authorization is logged in the organization's audit log, hash-chained like any other configuration change.

And if something goes wrong

You can revoke access at any time from Claude's connector settings. The refresh token stops working immediately. The access token, at most, in 15 minutes: that's its maximum lifetime even without revoking anything by hand.

The full technical reference, with every permission available today and which controller requires it, is in the MCP documentation.