For Admins
Enabling MCP Access
MCP access is off by default. An admin must enable it before any user in the organisation can connect an AI client. To enable MCP access:- Go to Settings → General → Pleo AI in the Pleo settings
- Under the MCP section, enable Pleo MCP access
Disabling MCP Access
Admins can disable MCP access for the entire organisation by turning off the toggle in Settings → General → Pleo AI.Staging Environment
The staging MCP server mirrors the production permission model. MCP access must also be enabled per entity in your staging Pleo account before connecting. See How to Install the Pleo MCP as a Custom MCP: Using Staging for setup steps.For Users
User Permission Model
The MCP server does not grant any new permissions. An agent acting on behalf of a user can only do what that user can already do in the Pleo product.- A spender can read and update their own expenses
- An agent cannot access data the connecting user cannot see in the Pleo app
Working Across Multiple Entities
If you have access to more than one Pleo entity, the agent can work in any of them without you reconnecting or re-authorising.- Each request targets one entity at a time. There is no “all entities at once” mode. The agent cannot combine data from two entities within a single request.
- Your default entity is used unless you say otherwise. This is the entity you connected during setup. To work in a different one, name it in your request, for example “show my expenses in Beta Ltd”.
- Naming the entity is not sticky. If you want to stay in a non-default entity across several requests, keep referring to it, or tell the agent to keep working in that entity.
- Each entity needs its own admin opt-in. An entity where MCP access hasn’t been enabled is not available to the agent, even if you have access to it in the Pleo app.
Revoking Your Access
Users can disconnect their own AI client’s MCP access. See How to Revoke Access to the Pleo MCP for the full steps.Audit Trail
Any action taken or data updated in Pleo are recorded in Pleo’s activity and audit logs. The actions are visible in the Activity tab for the relevant expense.Security Boundaries
- No payment actions. The MCP does not support wallet top-ups, reimbursement payouts, invoice payments, or any autonomous payment decisions. SCA and regulatory controls remain intact.
- No permission elevation. An agent cannot access data or take actions beyond the connected user’s existing Pleo permissions.