Precisely control what your AI apps can do in Plane

Toolsets let you decide exactly which actions an AI app can take, from read-only lookups to compensation changes.

Author

Last Update

Sample screenshot of toolsets and permission options with dark purple patterned gradient background

Table of Contents

Loading headings...

There's a good reason many HR teams hesitate to introduce AI to their HR and payroll platform. The data in it is about as sensitive as company data gets: salaries, home addresses, dependents, benefit elections. Connecting an MCP client to all of it is a tradeoff that many People teams don’t want to make.

That caution is understandable. If you give an AI app like Claude or ChatGPT read-only access, the AI app can answer questions but can’t actually complete the work for you. Give write access to the AI app, and you're potentially handing over far more access than the job actually requires.

Not anymore. We’ve launched toolsets, which let you define exactly what an AI app can see and do in Plane, category by category. They can now take real action on your data, and they can only take the actions you listed.

Granular control and increased security

It’s your data; you should control everything AI can do with it. And with toolsets, you do. 

When an admin creates a toolset, they set exactly what parts of Plane get Read permission and what parts get Read and write permission. Read means the app can look. Read and write means it can act.

Each area of Plane is divided into categories and sub-categories, and you get to set permissions by sub-category, giving you precise, granular control over what Plane’s MCP server can do:

  • People (including sub-categories of Worker contacts, Departments, Managers, and Offers)

  • Pay (with sub-categories of Payrolls, Compensations, and Deductions)

  • Money (including sub-categories of Payments, Charges, and Payment requests)

  • Time and Work (with sub-categories of Time off, Calendar events, Projects, and Tasks)

  • Benefits (including sub-categories of Benefit programs and Benefit plans)

  • Planning and rules (including sub-categories of Workforce plans, Labor rules, and Labor taxes)

  • Workspace (including sub-categories of Entities, Locations, Sandboxes, and API keys)

New toolsets are read-only by default. Write access is something you turn on deliberately for your workspace. A tool that isn’t in the toolset is never offered to the AI app, and if someone requests a tool that’s outside of the toolset, their request is rejected.

Nothing overrides access levels in Plane

A toolset never grants anyone access they don't already have in Plane. Let’s say an admin builds a toolset with write access to compensation and shares its URL with a coworker who holds a standard manager role. When that coworker connects it, the compensation tools are not in the list their AI app receives. A standard manager cannot change pay in Plane, and no toolset can add that permission.

LIVE WEBINAR · OCTOBER 14 · 10AM PT

Connect AI Agents to Your HR Stack

You know how to build a basic AI agent. Now power up your agent by connecting it with your HR data.

Can't join live? Register anyway and we'll send you the recording.

A separate connection for every job

Plane’s MCP server lets you set up multiple toolsets. Every toolset gets its own address, a URL unique to your workspace. Connect it to an AI app as a custom connector, sign in with your Plane account, and that app has the access you defined.

Because the addresses are separate, the jobs can be, too:

  • Expense report approvals: Create a toolset for an agent to automatically review and approve expense reports according to your company policy.

  • Compensation reviews: Set up a toolset with write access on compensation. Narrow, deliberate, and used by the people running the review.

Set up a toolset today

Toolsets are configured by a workspace admin in Plane, and they are currently free to try for all accounts. To create a toolset, go to the Toolsets section under Developers. Click New toolset in the upper right.

Learn more in our Help Center article.

Questions? Please contact our Support team. We’re happy to help.

Want product news & updates?

Sign up for our newsletter.

Asta So is a product marketing manager at Plane, where she covers product launches and company news. She has spent two decades in marketing and people ops for B2B SaaS companies and holds an MFA in creative writing.