Skip to content

How to Manage MCP for a Team

How-ToBlake Folgado
How to Manage MCP for a Team
Tools in this guideSeoLead FinderGenerate Image

To manage MCP for a team, approve one hosted catalog, have an owner add it in each assistant, share seats and credits, turn unused tools off, and remove access the day someone leaves. Personal npx servers in Cursor and one-off connectors in Claude do not add up to a company setup. They add up to twelve invoices and no list of who called what.

This is the operating playbook. Vendor comparisons live on Best MCP tools for teams and How companies centralize MCP. Product page: For teams.

The questions teams actually ask

QuestionShort answer
Can everyone use the same tools in Claude, ChatGPT, and Cursor?Yes, if you share one catalog instead of one server per person.
Who is allowed to add a new MCP server?On Claude Team and Enterprise, only an Owner can add a custom connector. Members then Connect.
How do we stop surprise bills?Shared credit pool plus per-member spending limits. Paid catalog skills start at $0.005. See pricing.
What happens when someone quits?Remove the seat. They lose the catalog. Rotate any keys they pasted into a local config.
Do we still need ChatGPT Team / Claude Team seats?Yes. ToolRouter sits *inside* those products. It does not replace them.
Can we see who ran which tool?Audit log on Business and above. Pricing.

The Model Context Protocol is the wire. It does not give you an org chart, a bill, or an offboarding button. That is the gap a team catalog fills.

A one-week setup that actually sticks

  1. Name an owner. One person adds connectors. Everyone else only connects to what the owner added. Anthropic is explicit: on Team and Enterprise, only Owners add custom connectors. Members click Connect. Copy that rule into Cursor and ChatGPT even where the product is looser.
  2. Stand up the shared catalog. Create a ToolRouter team at For teams. Invite seats. Default is the full catalog on; admins turn tools off.
  3. Add one connection per assistant, not per person. Claude (Team owners: this walkthrough). ChatGPT Developer mode. Cursor. Grok Bot. Same URL family, same bill.
  4. Cap spend on day one. Team is $29/seat/month with $20 of credits included. Business is $59/seat with $45 of credits and the audit log. Set a per-member limit so one image-to-video binge cannot empty the pool. How much MCP costs.
  5. Write the two-line policy. Approved catalog: ToolRouter. Local npx servers: not unless the owner said yes. Keys: never in a committed mcp.json. GitGuardian found 24,008 unique secrets in public MCP config files; 2,117 were still valid.
  6. Offboard like you mean it. Remove the seat. If they used BYOK, rotate that key. If they had a laptop mcp.json, treat it as a credential file.

What ToolRouter does and does not do for a team

JobToolRouterStill someone else
Same specialist tools in every assistantYesKeep Claude / ChatGPT / Cursor seats
Shared credits and seat listYesStripe invoice is the bill
Turn a tool off for the companyYes (admin)The assistant may still have its own built-ins
Spend cap per personYesVideo and image skills are the ones that move the needle
Audit who called whatBusiness and aboveNot a SIEM. Export if your auditor needs more
Block customer PII in tool callsOptional PII filterNot a full DLP product; read the limits
Gmail / Salesforce as that employeeNoComposio, Zapier, or Arcade. We say so on best MCP tools for teams
Run the gateway in your VPCNoTrueFoundry

If legal already wrote “HIPAA, BAA, self-host” into the RFP, start with that vendor and keep ToolRouter for the specialist catalog only if it still fits. Honesty here saves a wasted pilot.

Give your AI superpowers. Copy one instruction and paste it into your AI.

A policy you can paste into Notion

text
Approved MCP: ToolRouter (https://api.toolrouter.com/mcp).
Claude Team: only Owners add connectors. Members click Connect.
Cursor: no extra servers in project mcp.json without an owner yes.
Secrets: never commit API keys in mcp.json. Use the hosted catalog or env vars.
Offboard: remove the ToolRouter seat the same day as the Claude/ChatGPT seat.

That is enough for a ten-person startup. Expand it when you have a security person.

For the security version of this problem, see How to stop shadow MCP at a startup.

Create the team on For teams, add the connector once, and invite seats.

Frequently Asked Questions

Is this instead of Claude Team or ChatGPT Team?

**No.** Those seats are the assistants. ToolRouter is the shared tool catalog those assistants call.

Can contractors use it?

**Yes, as a seat.** Remove the seat when the contract ends. Do not share one login.

Do we need the audit log on day one?

**Not if you are five people and you trust each other.** Turn it on (Business) before you give the catalog to a wider group or before a customer asks who ran what.

What if people keep installing random MCP servers anyway?

**That is shadow MCP.** Block it in Claude at the org connector list, and say so in writing for Cursor. Walkthrough: [stop shadow MCP](/blog/how-to-stop-shadow-mcp-at-a-startup).

B
Founder at ToolRouter
Share this article

Related Posts