Skip to main content

Use toolsets to control what an AI app can do in Plane

Learn how toolsets specify the exact set of read and write tools an AI app can use.

Overview

Plane's connector, also called an MCP server, provides read-only tools by default. When you connect an MCP client like Claude to Plane, it can read across your workers, payroll, expenses and time off and answer questions from live data, but it has no tools that change anything. That default is deliberate because it is a safe starting point.

A toolset controls which tools an MCP client like Claude can use. You set a permission on each area of Plane and the tools follow: read workers, write expense reports, and so on. What you can choose depends on the area. Most offer Read or Read and write, and a few also offer combinations that include proposing or approving.

Limits on what a toolset can do

A tool the toolset doesn't include is never offered to the AI app, and a request for it will be rejected. No instruction can talk the AI app into an action its toolset doesn't allow.

In addition, each user's permissions in Plane always take precedent over what the toolset allows. Whoever connects to the toolset signs in as themselves, so what they can actually do is the overlap between the toolset's list and their own Plane permissions. For example, if a manager uses a toolset in Claude that has permission to change compensation, the manager still won't be able to ask Claude to change someone's compensation, since the manager's Plane user permissions don't allow it.

How a toolset works

Each toolset has two parts:

  • An address — a URL, unique to your workspace, in the form https://api.plane.com/mcp/toolset_9fKp2mQvXn4RtB

  • A list of permissions — what the AI app may read in each area, and which actions it may take

The permissions decide which tools the AI app is offered. Grant read on expenses and it gets the tools for reading them, and nothing else.

Plane administrators can configure one or more toolsets for a workspace, each with its own set of permissions. For example, a toolset could keep read access to everything and add the ability to approve expense reports. Or it could be tighter on both sides: read expense reports and time off requests only, and act on just those.

Creating a toolset

Admins can create toolsets. To create a toolset, follow these steps:

  1. Go to the Toolsets section under Developers.

  2. Click New toolset in the upper right.

  3. Enter a name for the toolset.

  4. Click Add in the Permissions section and choose the areas the AI app should reach.

  5. Click Create toolset.

New toolsets start read-only. If you need writes, start with the narrowest set your team needs and widen once you have seen it run.

Changing a toolset

Edit toolsets at any time by clicking Edit in the upper right of the toolset's details page. A change applies to connections that are already open. If a tool is removed, the next attempt to use it is refused. Reconnect the assistant afterwards so its list matches.

Connecting and using your AI app

Connecting to a toolset works exactly like connecting to Plane normally: add it as a custom connector and sign in with your Plane account. The only difference is the address — use the toolset address Plane sent you instead of the standard one.

Set up Plane MCP has step-by-step instructions for Claude and ChatGPT, along with troubleshooting.

Once connected, you can use the toolset to review and approve payroll, approve expenses, decline a time off request, and anything else on its list. A good habit is to look before you act: ask the assistant to show you the records first, then tell it which ones to act on.

Sending us feedback

Toolsets are new, and the set of available actions is growing. If your assistant can't do something you expected, or a result comes back confusing or wrong, don't hesitate to get in touch. That feedback directly shapes what gets built next.

Did this answer your question?