We're excited to introduce a new layer of security controls for the Box MCP Server. Box admins can now control which Box MCP Server tools each unpublished platform app is allowed to use. For every app—regardless of authentication method—admins can apply the organization-wide MCP policy or create a custom set of permitted tools specifically for that app. This gives organizations the same granular governance for their internal, custom-built apps that was previously available only for published integrations.
What's new
Every platform app listed in Admin Console > Platform > Platform Apps now includes its own Box MCP Server tab. From there, admins can define exactly which tools that specific app is allowed to use, independently of the organization-wide global controls.
To find it: go to Admin Console > Platform > Platform Apps, locate the app by name, click to open it, and select the Box MCP Server tab.
Admins can now:
- Choose between Global and Custom configuration for each unpublished platform app. Global inherits the organization's global MCP settings; Custom lets you define a set of tools scoped to that app alone.
- Enable or disable individual tools within a Custom configuration, grouped by category — such as Files and Folders, Search, or Collaboration.
- Grant a trusted internal app broader or different access than the global default without affecting any other app.
- Revert to the organization's global policy at any time by switching from Custom back to Global.
Why it matters
Because unpublished apps are typically internal or custom-built and haven’t undergone Box’s app-publishing review, admins need more granular control over what each app can access. These controls help enforce least-privilege access by ensuring each app can call only the tools it genuinely needs. They also give admins one consistent way to govern both published and unpublished MCP-connected apps across their organization.