How to Manage MCP for a Team

To manage MCP for a team, approve one hosted catalog, have an owner add it in each assistant, share seats and credits, turn unused tools off, and remove access the day someone leaves. Personal npx servers in Cursor and one-off connectors in Claude do not add up to a company setup. They add up to twelve invoices and no list of who called what.
This is the operating playbook. Vendor comparisons live on Best MCP tools for teams and How companies centralize MCP. Product page: For teams.
The questions teams actually ask
| Question | Short answer |
|---|---|
| Can everyone use the same tools in Claude, ChatGPT, and Cursor? | Yes, if you share one catalog instead of one server per person. |
| Who is allowed to add a new MCP server? | On Claude Team and Enterprise, only an Owner can add a custom connector. Members then Connect. |
| How do we stop surprise bills? | Shared credit pool plus per-member spending limits. Paid catalog skills start at $0.005. See pricing. |
| What happens when someone quits? | Remove the seat. They lose the catalog. Rotate any keys they pasted into a local config. |
| Do we still need ChatGPT Team / Claude Team seats? | Yes. ToolRouter sits *inside* those products. It does not replace them. |
| Can we see who ran which tool? | Audit log on Business and above. Pricing. |
The Model Context Protocol is the wire. It does not give you an org chart, a bill, or an offboarding button. That is the gap a team catalog fills.
A one-week setup that actually sticks
- Name an owner. One person adds connectors. Everyone else only connects to what the owner added. Anthropic is explicit: on Team and Enterprise, only Owners add custom connectors. Members click Connect. Copy that rule into Cursor and ChatGPT even where the product is looser.
- Stand up the shared catalog. Create a ToolRouter team at For teams. Invite seats. Default is the full catalog on; admins turn tools off.
- Add one connection per assistant, not per person. Claude (Team owners: this walkthrough). ChatGPT Developer mode. Cursor. Grok Bot. Same URL family, same bill.
- Cap spend on day one. Team is $29/seat/month with $20 of credits included. Business is $59/seat with $45 of credits and the audit log. Set a per-member limit so one image-to-video binge cannot empty the pool. How much MCP costs.
- Write the two-line policy. Approved catalog: ToolRouter. Local
npxservers: not unless the owner said yes. Keys: never in a committedmcp.json. GitGuardian found 24,008 unique secrets in public MCP config files; 2,117 were still valid. - Offboard like you mean it. Remove the seat. If they used BYOK, rotate that key. If they had a laptop
mcp.json, treat it as a credential file.
What ToolRouter does and does not do for a team
| Job | ToolRouter | Still someone else |
|---|---|---|
| Same specialist tools in every assistant | Yes | Keep Claude / ChatGPT / Cursor seats |
| Shared credits and seat list | Yes | Stripe invoice is the bill |
| Turn a tool off for the company | Yes (admin) | The assistant may still have its own built-ins |
| Spend cap per person | Yes | Video and image skills are the ones that move the needle |
| Audit who called what | Business and above | Not a SIEM. Export if your auditor needs more |
| Block customer PII in tool calls | Optional PII filter | Not a full DLP product; read the limits |
| Gmail / Salesforce as that employee | No | Composio, Zapier, or Arcade. We say so on best MCP tools for teams |
| Run the gateway in your VPC | No | TrueFoundry |
If legal already wrote “HIPAA, BAA, self-host” into the RFP, start with that vendor and keep ToolRouter for the specialist catalog only if it still fits. Honesty here saves a wasted pilot.
Give your AI superpowers. Copy one instruction and paste it into your AI.
A policy you can paste into Notion
Approved MCP: ToolRouter (https://api.toolrouter.com/mcp).
Claude Team: only Owners add connectors. Members click Connect.
Cursor: no extra servers in project mcp.json without an owner yes.
Secrets: never commit API keys in mcp.json. Use the hosted catalog or env vars.
Offboard: remove the ToolRouter seat the same day as the Claude/ChatGPT seat.That is enough for a ten-person startup. Expand it when you have a security person.
For the security version of this problem, see How to stop shadow MCP at a startup.
Create the team on For teams, add the connector once, and invite seats.
Frequently Asked Questions
Is this instead of Claude Team or ChatGPT Team?
**No.** Those seats are the assistants. ToolRouter is the shared tool catalog those assistants call.
Can contractors use it?
**Yes, as a seat.** Remove the seat when the contract ends. Do not share one login.
Do we need the audit log on day one?
**Not if you are five people and you trust each other.** Turn it on (Business) before you give the catalog to a wider group or before a customer asks who ran what.
What if people keep installing random MCP servers anyway?
**That is shadow MCP.** Block it in Claude at the org connector list, and say so in writing for Cursor. Walkthrough: [stop shadow MCP](/blog/how-to-stop-shadow-mcp-at-a-startup).


