Skip to main content

Elements MCP server security, data access and admin controls

What the Elements MCP server can access, how sign-in and Space permissions work, and how to audit or revoke AI assistant connections.

The Elements MCP (Model Context Protocol) server lets an AI assistant such as Claude, ChatGPT or Cursor understand your Salesforce configuration and documentation through interacting with Elements metadata graph, using the Elements permissions you already have.

This article explains what the Elements MCP server can access, how sign-in works, how Space access is controlled, and how to review, audit and revoke connections. It's the article to share with your security team.

The Elements MCP server never connects to your Salesforce org.

  • It reads only the deterministically processed metadata graph of your Salesforce Org Elements has already synced.
    ​

  • It can't reach Salesforce business records such as accounts, contacts or opportunities etc.
    ​

  • And nothing it does can change your Salesforce org configuration.

Prerequisites

  • Elements has enabled MCP access for the Space you want to use. MCP access is a licensed feature, available to customers on Advanced Metadata Management plan
    ​

  • A Salesforce Org is connected and synced to that Space.
    ​

  • An AI assistant that supports remote MCP servers with the MCP standard's secure sign-in (OAuth 2.1 with PKCE). Elements has been tested with Claude (CLI and Cowork), Codex CLI, ChatGPT (Work) and Cursor.
    ​

  • Permission to add a custom connector or MCP server in that assistant. In many companies only an IT administrator can do this.
    ​

  • Your Elements sign-in. You sign in with your existing Elements account, the same way you do in the browser.

What the Elements MCP server can access

The Elements MCP server can access the Salesforce metadata graph, i.e. deterministically processed, deep understanding of how your Salesforce Org is configured that Elements stores, such as permission configuration, automation dependencies, schema relationships, and others.

There is no path from your AI assistant to your Salesforce org. Elements does not see, sync, store or expose your Org's actual data.

Some Elements MCP tools also expose usage telemetry: record counts, and automation execution telemetry from Salesforce Event Monitoring logs. Elements never stores Salesforce business records (accounts, contacts, opportunities, transactions), so an AI assistant connected through Elements can't reach them either.

Your AI assistant connects to the Elements MCP server over a secure, authenticated HTTPS connection. On every request, the server checks your identity, the Spaces you approved, and your Elements role, plan and licences before it reaches your Space.

What an AI assistant can create or change in Elements

Most Elements MCP tools are read-only. A small set can create or change these things, inside Elements only:

  • New workspace

  • Diagram

  • User story record

  • Proposed metadata in metadata dictionary: a placeholder marked "proposed" for people to review, not a change to your org

  • MetaFields (custom fields your Space defines on metadata) and their values

The Elements MCP server has no delete tool. It never creates, updates, deletes or deploys Salesforce metadata, and it never overwrites the synced copy of your org in Elements.

How sign-in works

You sign in to the Elements MCP server with your existing Elements account using OAuth 2.1, an open sign-in standard used across the industry. The sign-in flow uses PKCE (Proof Key for Code Exchange), an extra safeguard that stops an intercepted request from being reused by anyone else. You sign in through your browser, directly with Elements, so your Elements password is never shared with your AI assistant.

When you approve a connection, Elements shows you the client (for example, Claude Code) and the scope families it requests. Clients are offered the same full scope set by default, though a client may request fewer; you don't pick scopes. The choice you make is which Space or Spaces the connection can use.

How Space access and permissions are controlled

An AI assistant connected to Elements never gets more access than you already have in Elements. Three things decide what a connection can do:

  • Space licensing: Elements enables MCP access for each Space individually. A Space that hasn't been enabled can't be selected when you connect. Elements checks this on every request, so disabling a Space takes effect immediately, even for connections approved earlier.
    ​

  • Your consent: a connection only works in the Spaces you selected when you approved it, and new Spaces are never added to an existing connection automatically. To change which Spaces a connection can use, revoke it and reconnect.
    ​

  • Your Elements permissions: every request is checked against your Elements role, plan and permissions at the moment it's made, so if your access changes, what your assistant can see changes with it. Approving a connection never raises your Elements permissions, and your assistant can never do more than your Space administrator allows you to do yourself.

A connection can't be used to reach any other Space, tenant or customer's data. Each access token is cryptographically tied to the Elements MCP server, so even an exposed token couldn't be replayed against another Elements service.

Token handling

Elements MCP access tokens are short-lived and refresh automatically in the background. Refresh tokens rotate on each use and last 30 days from the last refresh, so a connection used at least once a month stays signed in. Elements never stores a token in plain text; it keeps only a keyed hash (HMAC-SHA-256).

How to review and revoke connections

You can review and revoke your own AI assistant connections to Elements at any time:

  1. Open your Elements profile.

  2. Select the 'Connected apps' tab.

  3. Find the connection and click 'Revoke'.

The 'Connected apps' tab shows each connection's client, the Spaces it can use, its scope, and when it last signed in. Space administrators can review the connections into their Space and remove their Space from them. Revoking or removing a connection takes effect immediately.

Removing the Elements server from your AI assistant's settings stops that assistant using it, but the connection stays valid in Elements until its refresh token expires, 30 days after its last refresh. To end a connection immediately, revoke it in 'Connected apps'.

Audit logging

Elements logs every action an AI assistant takes through the MCP server: who made the request, which Space it ran in, what it asked for, and whether it succeeded. Sign-ins, approvals and revocations are logged too. The records are kept in tamper-resistant storage operated by Elements and are used for security monitoring and incident investigation.

Audit logs aren't visible in the Elements app today. To have a connection's activity investigated, contact Elements support. What you can see yourself, at any time, is every active connection on the 'Connected apps' tab of your profile.

Rate limits and safeguards

Each Elements MCP connection is limited to a safe rate of requests, and every request is checked against a strict, predefined set of allowed inputs before it runs, so it can't be used to send unexpected commands. Responses are screened too: hidden characters that could smuggle instructions to an AI assistant are stripped, and AI-generated explanations are marked so your assistant treats them as information to read, not instructions to follow.

The most significant changes are saved as drafts for a person to review in Elements. A proposed metadata node is marked as proposed in your reference model, and an imported diagram only updates the diagram's working draft; publishing an approved version is a separate, deliberate step.

AI features and your data

Some Elements MCP tools use a large language model (LLM) to produce answers: explaining a metadata item, the Decision Engine analyses, and generating process maps and user stories. These tools run through the same licensed AI features Elements already offers in the web app, so connecting an AI assistant doesn't add a new AI integration or send your data anywhere new.

Only the metadata needed to answer the question is sent, never Salesforce business records, which Elements doesn't hold. AI-generated text is screened and marked as untrusted data, and Decision Engine runs keep their analysis as internal Elements artifacts. The full list of AI-backed tools is in the Elements MCP server tools reference.

Security certifications

The Elements MCP server runs on the same platform as the rest of Elements. Elements' platform security documentation, including SOC 2, ISO 27001:2022 and the Data Processing Agreement, is available at trust.elements.cloud.

Frequently Asked Questions

Is my data stored outside Elements when I connect an AI assistant?

Connecting an AI assistant doesn't store your data anywhere new. The Elements MCP server reads from the same Elements data your account can already access, and the connection itself creates no additional copy.

Can an AI assistant change my Salesforce org through Elements?

An AI assistant can't change your Salesforce org through Elements. The Elements MCP server never connects to Salesforce, and it never creates, updates, deletes or deploys Salesforce metadata.

Can an AI assistant see my Salesforce records through Elements?

An AI assistant can't see your Salesforce records through Elements, because Elements never stores business records such as accounts, contacts, opportunities or transactions. It works only with metadata, configuration and usage telemetry.

Who can revoke an AI assistant's access to a Space?

You can revoke your own connections on the 'Connected apps' tab of your Elements profile, and Space administrators can remove their Space from any connection into it. Elements can also disable MCP access for a whole Space. All three take effect immediately.

Did this answer your question?