AI Security & Admin Checklist
Before rolling out Claude or ChatGPT with Flourish: who can use it, what it can change, how to audit it, and how to keep your data private.
Connecting an AI assistant such as Claude or ChatGPT to Flourish lets your team ask questions and get work done in plain language. Before you roll it out, ask the questions you'd ask of any system that can see and change your business data. This article answers them for Flourish.
1. What can it do?
The AI can only use the tools Flourish exposes through the MCP server. Most are read tools: they look up inventory, orders, items, BOMs and reference data. A smaller set of write tools create or change records. Examples include drafting a wholesale order, updating item fields, locking packages, staging an inbound transfer, and drafting a BOM or work order.
Write tools are deliberately narrow. For example, the order tool creates a draft and never allocates, submits, ships, invoices or takes payment. The manufacturing tools never start or complete a run. Only one tool reports anything to Metrc or BioTrack: locating a package. Each tool article lists exactly what it does.
2. How could it get things wrong?
AI assistants are good at this work, but they can misread a document or pick the wrong item when two look alike. The protection is the approval step: keep write tools on "Needs approval" so the assistant must show you exactly what it will do and wait for your yes. Read the preview before you approve. Treat it the way you would review a new employee's work.
3. How do I control it?
There are two layers of control:
Where | Control |
In Flourish (Admin → Integrations → MCP Server) | MCP Enabled: nothing works for a user until an admin turns this on. Full Access: allows write tools; leave it off for read-only users. Disconnect: revokes a user's AI connection immediately. Normal Flourish roles and facility access still apply. |
In your AI client (Claude or ChatGPT) | Set each Flourish tool to always allow, needs approval, or blocked. We recommend Always allow for read tools and Needs approval for every write tool to start. Block any tool you never want used, for example all order tools. You can also turn off tool groups you don't use, such as manufacturing or retail. |
4. What data can it see, and is it private?
The AI sees only what the signed-in user can see in Flourish, limited to their facilities. When a read tool returns data, that data is sent to your AI provider to answer the question. Protect it at the provider:
- Use a business plan (for example Claude Team or Enterprise, or ChatGPT Business or Enterprise) rather than a personal account.
- In your organization's privacy or data settings, confirm that chats are not used for model training. Business plans generally have training off by default, but it's worth checking.
5. Who can use it, and how do I see what they did?
- Every user connects with their own Flourish login. There is no shared account. Connections expire after 90 days.
- A user who connects without MCP enabled can only confirm who they are signed in as. They can't read or change anything.
- On Admin → Integrations → MCP Server, you can see who is connected, from which client (Claude, ChatGPT…), and when they last used it.
- Click View audit log to review every tool call by user, tool, result and date. Records changed through AI also show the user as last modified, the same as changes made in the app..
Recommended starting setup
- Enable MCP for a small pilot group first, and give Full Access only to users who need to make changes.
- In your AI client, set read tools to Always allow and write tools to Needs approval.
- Confirm training is off in your AI provider's organization settings.
- Review the audit log after the first week.
- Widen access once your team is comfortable.
How did we do?
Choosing a Model and Writing Good Prompts