We're excited to introduce new controls in the Admin Console for published Box MCP server integrations. Admins can now set tool configurations at two levels: one that applies organization-wide, and a separate configuration for each MCP-based published integration.
Global admin controls let organizations define a single policy across all AI agents, but admins often want a specific AI platform to have tool access that differs from the organization-wide default. These new controls make that possible, so each connected AI platform can be governed on its own terms without changing the policy for everything else.
What's new
Every integration published in the Box Integration Catalogue under the MCP category now includes its own Box MCP server tab in the Admin Console. From there, admins can define tool access for that specific third-party AI platform rather than for the entire enterprise at once. To find it, go to Admin Console > Integrations, locate the integration by filtering to the MCP category or searching by name, then click the integration name to open its modal and select the Box MCP server tab.
Admins can now:
- Choose between Global and Custom configuration for each published AI platform. Global inherits the organization's global MCP settings; Custom lets you define a set of tools scoped to that integration alone.
- Enable or disable individual tools within a Custom configuration, grouped by category — such as Files and Folders, Search, or Collaboration.
- Grant a trusted platform broader access, or lock down a higher-risk one, without changing the experience for any other connected AI platform.
- Revert to the organization's global policy at any time by switching from Custom back to Global.
Default behavior
By default, every integration continues to respect your organization-wide configuration. That global policy stays in effect unless you set a Custom configuration on the integration, in which case the integration-specific settings take precedence. Any tool disabled for an integration is automatically hidden from end users in that integration, which means a single Box MCP server can offer different capabilities from one integration to the next.