How control works
Two separate layers decide what a person can do.- Your AI client’s tool policy. You set each tool to run automatically, ask for approval each time, or stay off. This is where you require approval for changes.
- allGood permissions. Each person’s allGood role decides which actions succeed. Lookups need View, Use, or Manage on Campaigns. Edits need Use or Manage. Cloning needs Manage.
Recommended tool policy
For the full tool list, see Finding programs and working with data and Editing and sending emails.
Set up your AI client
The steps differ by client. The recommended policy is the same.- Claude
- ChatGPT
You need to be an Owner on a Claude Team or Enterprise plan.Policy changes can take up to 15 minutes to reach members. You can change them again at any time.
1
Add the connector for your organization
- Go to Organization settings > Connectors
- Click Add, hover over Custom, and select Web
- Enter the name
allGood Marketoand the URLhttps://api.allgoodhq.app/mcp/marketo, then click Add
2
Set the tool policy
- Open the allGood Marketo connector and go to its tool permissions
- Set read-only tools to Always allow
- Set write and delete tools to Needs approval
3
Allow image uploads (optional)
Skip this step if your team won’t upload images to Design Studio. Everything else works without it.
- Go to Organization settings > Capabilities
- Set network access to Allow network egress to package managers and specific domains
- Add
api.allgoodhq.appand save your changes
4
Tell members to connect
Members open Customize > Connectors, find allGood Marketo, and click Connect. They sign in with their own allGood account. See Using with Claude Desktop for what they’ll see.
The organization policy is a ceiling. Members and role grants can’t override it.
Other AI clients
The allGood Marketo MCP is set up for Claude and ChatGPT today. Here’s where other AI clients stand. Gemini Enterprise: We’re interested in exploring the allGood Marketo MCP with Gemini Enterprise. It isn’t a supported setup yet. If your organization uses Gemini Enterprise and would like to explore it, contact allGood support or your account team. Gemini in Google Workspace: This connects only to a fixed list of partner apps chosen by Google, and allGood isn’t on it. Admins manage that list at Apps > Google Workspace > Gemini for Workspace > Third-Party Connectors. Gemini app: Custom MCP connections are available only to personal Google Accounts, not work or school accounts. Google provides no admin controls for them, and allGood doesn’t support this as a managed setup. Microsoft Copilot Studio: We’re interested in exploring the allGood Marketo MCP with Copilot Studio. It isn’t a supported setup yet. If your organization uses Copilot Studio and would like to explore it, contact allGood support or your account team.Confirm it works
These checks apply whichever client you set up.- Ask a member to run a lookup, such as “Using allGood Marketo, look up the program details for [program name].” It should return data with no approval prompt.
- Ask the same member to update a token on a test program. The client should ask for approval before it runs.
- In allGood, go to Settings → MCP Usage. Both calls should appear with the member’s name, the tool, and the full input and output.
Troubleshooting
Members can't see the connector
Members can't see the connector
In Claude, confirm you added it under Organization settings > Connectors and that members have refreshed. In ChatGPT, confirm custom connectors are turned on for their role.
A change ran without asking for approval
A change ran without asking for approval
Check that the tool is set to require approval and not to run automatically. On ChatGPT Business, approval prompts aren’t guaranteed. Use allGood roles to limit changes.
A member sees an allGood permission error
A member sees an allGood permission error
The person’s allGood role doesn’t include the action. Ask an allGood admin to review their Campaigns permission.
Image uploads fail
Image uploads fail
In Claude, add
api.allgoodhq.app to the domain allowlist. See the optional step above.