The question before you connect anything
Before connecting Claude or ChatGPT to a planner that holds real work — client names, meeting notes, sometimes sensitive project details — the obvious question comes first: once it's connected, does the AI just have everything? Does it read the whole workspace by default? Does any of that content end up sitting on someone else's server?
The honest answer is that the connection itself isn't the risky part. What matters is the permission model underneath it — and it's built to ask before it does anything, not after.
Every request asks first — every single time
Connecting xTiles to Claude doesn't hand over blanket access to the whole workspace. Every time the AI needs to reach a specific page or project, it asks: can I go there? You approve or decline that one request. There's no background access running quietly once the connection is set up — permission is requested per action, not granted once and forgotten.
That also means you can say no. If a request touches something you'd rather keep out of the conversation, declining doesn't break the connection — it just means that one specific action doesn't happen.
Keep sensitive content in its own project
There's no need to trust the AI with everything just because it's connected. Passwords, client-sensitive material, or anything else you'd rather not surface can live in its own project or workspace, with a plain instruction attached: don't use this project for requests, or only use it when I specifically ask.
The same applies more broadly — you can tell Claude, in plain language, to only pull from a specific project for a given request instead of searching everywhere. Scoping access is a conversation, not a settings page you have to dig through.
Nothing sits on Claude's servers between requests
The MCP connection doesn't work like a constant sync that mirrors your planner somewhere else. Claude reads xTiles content only at the moment it's asked to — you request a review of a project or page, it reads that, and returns the result. There's no ongoing background copy of your workspace being kept and updated on the AI side between conversations.
That distinction matters: an integration that constantly indexes your data behaves very differently from one that only looks when you point it somewhere and ask a question.
What the AI can and cannot do once connected
Day to day, that permission model applies to reading and creating content — new pages, new tiles, new tasks — the same way it applies to modifying something that already exists: only when you explicitly ask for the change. What it doesn't do on its own is delete anything. Building or updating your workspace through the connection adds to it or changes what you pointed at — it doesn't quietly remove things you didn't mention.