Skip to main content
This guide is for IT admins who are approving the allGood Marketo MCP and setting it up for a team. You’ll add the connector once, decide which actions run on their own and which need a person’s approval, and check that the setup works. It takes about 15 minutes. Most admins want the same outcome: lookups run freely, and anything that changes Marketo asks first. Both Claude and ChatGPT can enforce that for the whole workspace, so members can’t loosen it themselves. For a data-flow and access review, see Marketo MCP: security, data, and governance. This article covers setup only.

How control works

Two separate layers decide what a person can do.
  • Your AI client’s tool policy. You set each tool to run automatically, ask for approval each time, or stay off. This is where you require approval for changes.
  • allGood permissions. Each person’s allGood role decides which actions succeed. Lookups need View, Use, or Manage on Campaigns. Edits need Use or Manage. Cloning needs Manage.
The tool policy narrows what’s available. It never grants more than a person’s allGood role allows. The connector has no tools that delete or unapprove anything. One tool, removing a module from an email, is marked as destructive. Require approval for it like the other changes. For the full tool list, see Finding programs and working with data and Editing and sending emails.

Set up your AI client

The steps differ by client. The recommended policy is the same.
You need to be an Owner on a Claude Team or Enterprise plan.
1

Add the connector for your organization

  1. Go to Organization settings > Connectors
  2. Click Add, hover over Custom, and select Web
  3. Enter the name allGood Marketo and the URL https://api.allgoodhq.app/mcp/marketo, then click Add
2

Set the tool policy

  1. Open the allGood Marketo connector and go to its tool permissions
  2. Set read-only tools to Always allow
  3. Set write and delete tools to Needs approval
On Enterprise plans with custom roles, set the connector to Custom to see each tool as its own row. You can then set Always allow, Needs approval, or Blocked per tool, and grant different roles different access.
3

Allow image uploads (optional)

Skip this step if your team won’t upload images to Design Studio. Everything else works without it.
  1. Go to Organization settings > Capabilities
  2. Set network access to Allow network egress to package managers and specific domains
  3. Add api.allgoodhq.app and save your changes
4

Tell members to connect

Members open Customize > Connectors, find allGood Marketo, and click Connect. They sign in with their own allGood account. See Using with Claude Desktop for what they’ll see.
Policy changes can take up to 15 minutes to reach members. You can change them again at any time.
The organization policy is a ceiling. Members and role grants can’t override it.

Other AI clients

The allGood Marketo MCP is set up for Claude and ChatGPT today. Here’s where other AI clients stand. Gemini Enterprise: We’re interested in exploring the allGood Marketo MCP with Gemini Enterprise. It isn’t a supported setup yet. If your organization uses Gemini Enterprise and would like to explore it, contact allGood support or your account team. Gemini in Google Workspace: This connects only to a fixed list of partner apps chosen by Google, and allGood isn’t on it. Admins manage that list at Apps > Google Workspace > Gemini for Workspace > Third-Party Connectors. Gemini app: Custom MCP connections are available only to personal Google Accounts, not work or school accounts. Google provides no admin controls for them, and allGood doesn’t support this as a managed setup. Microsoft Copilot Studio: We’re interested in exploring the allGood Marketo MCP with Copilot Studio. It isn’t a supported setup yet. If your organization uses Copilot Studio and would like to explore it, contact allGood support or your account team.

Confirm it works

These checks apply whichever client you set up.
  1. Ask a member to run a lookup, such as “Using allGood Marketo, look up the program details for [program name].” It should return data with no approval prompt.
  2. Ask the same member to update a token on a test program. The client should ask for approval before it runs.
  3. In allGood, go to Settings → MCP Usage. Both calls should appear with the member’s name, the tool, and the full input and output.
If all three happen, the rollout is working and every change is attributed to the person who made it.

Troubleshooting

In Claude, confirm you added it under Organization settings > Connectors and that members have refreshed. In ChatGPT, confirm custom connectors are turned on for their role.
Check that the tool is set to require approval and not to run automatically. On ChatGPT Business, approval prompts aren’t guaranteed. Use allGood roles to limit changes.
The person’s allGood role doesn’t include the action. Ask an allGood admin to review their Campaigns permission.
In Claude, add api.allgoodhq.app to the domain allowlist. See the optional step above.
If you’re still stuck, contact allGood support and include the time of the call so we can find it in the MCP Usage log.