AI oversight for admins · Fieldproxy MCP
Every AI connection, visible and revocable
From Claude, ChatGPT or Copilot in Teams, on your live field service data, with a confirm step before anything changes.
Reply to Claude...
Illustration of Fieldproxy's MCP tools inside Claude, ChatGPT and Copilot. Names and data are examples.
Short answer
AI oversight for admins from ChatGPT, Claude or Copilot: how does it work?
Fieldproxy administrators can ask for every AI connection in the workspace, what each one did, usage by key, person and tool, and revoke any key or connected app. Every call is logged with the tool, key, person and outcome, and a revoked key is refused on the next request.
Last verified September 27, 2026
Real requests
What people ask, and the tools it calls
| You ask | Fieldproxy tools | You get |
|---|---|---|
| “Which AI apps are connected to our workspace?” | list_ai_connections | Every connected app and key |
| “What did the AI change yesterday?” | ai_activity_log | Every call with tool, person and outcome |
| “Who is using the AI most, and for what?” | ai_usage_summary | Usage by key, person and tool |
| “Revoke Sam's ChatGPT key” | revoke_ai_access | Refused from the next request |
The part nobody else does
Your AI can change the software, not just the data
Every other field service connector we checked (September 27, 2026) reads records and, at most, edits a few of them. Fieldproxy's MCP server can also build: new fields, screens, tables, automations and agents, made in a sandbox copy of your workspace and live only when you approve.
Add a field
Build a screen
Wire an automation
Create an agent
Add your own tools
Roll back anything
Read more: customise field service software with AI · build it with Claude or ChatGPT instead?
Guardrails
Your AI proposes. A person confirms.
Built for operations with branches, teams and an IT review, not a single login.
Nothing changes on one call
Every write, send or action is a proposal the user confirms within 30 minutes. Writes can be undone. More than 5 rows needs bulk permission, and more than 1,000 is refused.
Keys scoped like API keys
Limit a key to certain tables, certain rows ("only the North region's jobs"), hidden columns, insert/update/delete, and an expiry from 1 hour to 90 days. Postgres enforces the row limits.
Builds save as drafts
Apps and automations are checked against the database before they save, new automations and agents are saved switched off, and public apps are never changed.
Sends are limited
Email goes only from the user's own mailbox, at most 20 sends an hour per key, inside the workspace's quiet hours. A sandbox never sends.
Everything is logged
Every call is written to an audit log with the tool, key, person and outcome. Administrators see every key and connected app, and revoking one applies on the next request.
FAQ
Questions
- Can an admin see someone's key?
- No. Keys are shown once to their owner; an administrator can set one up that the person claims from their own screen, so the admin never sees it.
Explore Fieldproxy MCP
Start here
Use cases
More use cases