> ## Documentation Index
> Fetch the complete documentation index at: https://docs.allgoodhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roll out the Marketo MCP to your organization

> Add the allGood Marketo MCP for your whole workspace in Claude or ChatGPT, require approval for changes, and see where other AI clients stand.

This guide is for IT admins who are approving the allGood Marketo MCP and setting it up for a team. You'll add the connector once, decide which actions run on their own and which need a person's approval, and check that the setup works. It takes about 15 minutes.

Most admins want the same outcome: lookups run freely, and anything that changes Marketo asks first. Both Claude and ChatGPT can enforce that for the whole workspace, so members can't loosen it themselves.

For a data-flow and access review, see [Marketo MCP: security, data, and governance](/use-cases/marketo-mcp/security-and-governance). This article covers setup only.

## How control works

Two separate layers decide what a person can do.

* **Your AI client's tool policy.** You set each tool to run automatically, ask for approval each time, or stay off. This is where you require approval for changes.
* **allGood permissions.** Each person's allGood role decides which actions succeed. Lookups need **View**, **Use**, or **Manage** on Campaigns. Edits need **Use** or **Manage**. Cloning needs **Manage**.

The tool policy narrows what's available. It never grants more than a person's allGood role allows. The connector has no tools that delete or unapprove anything. One tool, removing a module from an email, is marked as destructive. Require approval for it like the other changes.

## Recommended tool policy

| Tool group | Examples | Suggested setting |
| - | - | - |
| Lookups | Search programs, campaigns, folders, and forms. Get program details, email details, templates, and tokens. | Run automatically |
| Changes | Update tokens or program tags. Add, remove, rearrange, or edit email modules and content. Upload an image. | Require approval |
| Cloning | Clone a program. Clone an email. | Require approval |
| Test sends | Send a sample email to one address. | Require approval |

For the full tool list, see [Finding programs and working with data](/use-cases/marketo-mcp/capabilities) and [Editing and sending emails](/use-cases/marketo-mcp/capabilities-editing-emails).

## Set up your AI client

The steps differ by client. The recommended policy is the same.

<Tabs>
  <Tab title="Claude">
    You need to be an **Owner** on a Claude Team or Enterprise plan.

    <Steps>
      <Step id="claude-add-connector" title="Add the connector for your organization">
        1. Go to **Organization settings > Connectors**
        2. Click **Add**, hover over **Custom**, and select **Web**
        3. Enter the name `allGood Marketo` and the URL `https://api.allgoodhq.app/mcp/marketo`, then click **Add**
      </Step>

      <Step id="claude-set-policy" title="Set the tool policy">
        1. Open the **allGood Marketo** connector and go to its tool permissions
        2. Set read-only tools to **Always allow**
        3. Set write and delete tools to **Needs approval**

        On Enterprise plans with custom roles, set the connector to **Custom** to see each tool as its own row. You can then set **Always allow**, **Needs approval**, or **Blocked** per tool, and grant different roles different access.
      </Step>

      <Step id="claude-domain" title="Allow image uploads (optional)">
        Skip this step if your team won't upload images to Design Studio. Everything else works without it.

        1. Go to **Organization settings > Capabilities**
        2. Set network access to **Allow network egress to package managers and specific domains**
        3. Add `api.allgoodhq.app` and save your changes
      </Step>

      <Step id="claude-members" title="Tell members to connect">
        Members open **Customize > Connectors**, find **allGood Marketo**, and click **Connect**. They sign in with their own allGood account. See [Using with Claude Desktop](/use-cases/marketo-mcp/claude-desktop) for what they'll see.
      </Step>
    </Steps>

    Policy changes can take up to 15 minutes to reach members. You can change them again at any time.

    <Note>
      The organization policy is a ceiling. Members and role grants can't override it.
    </Note>
  </Tab>

  <Tab title="ChatGPT">
    Custom MCP connectors are available on ChatGPT Business, Enterprise, and Edu plans. The steps differ by plan.

    <Steps>
      <Step id="chatgpt-enable" title="Turn on custom connectors">
        **Business:** Go to **Workspace settings > Permissions & roles** and turn on **Developer mode / Create custom MCP connectors**.

        **Enterprise and Edu:** Go to **Settings > Apps > Advanced settings**. You can also grant the permission to specific members under **Permissions & roles > Connected data**.
      </Step>

      <Step id="chatgpt-add" title="Add the connector">
        Add an MCP server with the name `allGood Marketo`, type **Streamable HTTP**, and the URL `https://api.allgoodhq.app/mcp/marketo`. Authenticate with OAuth. The field-by-field walkthrough is in [Using with ChatGPT Desktop](/use-cases/marketo-mcp/chatgpt-desktop).
      </Step>

      <Step id="chatgpt-actions" title="Turn off actions you don't want (Enterprise and Edu)">
        1. Go to **Workspace settings > Apps**
        2. Click the ellipsis menu next to **allGood Marketo** and select **Action control**
        3. Turn off any action your team shouldn't have
      </Step>
    </Steps>

    <Note>
      On ChatGPT Business, admins can't change a connector's actions after it's published, and ChatGPT decides for itself when to ask for confirmation on changes. If you need a firm guarantee, limit what people can do through their allGood roles. A role with **View** on Campaigns can look things up but can't edit or clone.
    </Note>

    OpenAI doesn't verify custom connectors. Confirm that your security team has reviewed the allGood Marketo MCP before you add it.
  </Tab>
</Tabs>

## Other AI clients

The allGood Marketo MCP is set up for Claude and ChatGPT today. Here's where other AI clients stand.

**Gemini Enterprise:** We're interested in exploring the allGood Marketo MCP with Gemini Enterprise. It isn't a supported setup yet. If your organization uses Gemini Enterprise and would like to explore it, contact [allGood support](mailto:support@allgoodhq.com) or your account team.

**Gemini in Google Workspace:** This connects only to a fixed list of partner apps chosen by Google, and allGood isn't on it. Admins manage that list at **Apps > Google Workspace > Gemini for Workspace > Third-Party Connectors**.

**Gemini app:** Custom MCP connections are available only to personal Google Accounts, not work or school accounts. Google provides no admin controls for them, and allGood doesn't support this as a managed setup.

**Microsoft Copilot Studio:** We're interested in exploring the allGood Marketo MCP with Copilot Studio. It isn't a supported setup yet. If your organization uses Copilot Studio and would like to explore it, contact [allGood support](mailto:support@allgoodhq.com) or your account team.

***

## Confirm it works

These checks apply whichever client you set up.

1. Ask a member to run a lookup, such as "Using allGood Marketo, look up the program details for \[program name]." It should return data with no approval prompt.
2. Ask the same member to update a token on a test program. The client should ask for approval before it runs.
3. In allGood, go to **Settings → MCP Usage**. Both calls should appear with the member's name, the tool, and the full input and output.

If all three happen, the rollout is working and every change is attributed to the person who made it.

## Troubleshooting

<AccordionGroup>
  <Accordion title="Members can't see the connector">
    In Claude, confirm you added it under **Organization settings > Connectors** and that members have refreshed. In ChatGPT, confirm custom connectors are turned on for their role.
  </Accordion>

  <Accordion title="A change ran without asking for approval">
    Check that the tool is set to require approval and not to run automatically. On ChatGPT Business, approval prompts aren't guaranteed. Use allGood roles to limit changes.
  </Accordion>

  <Accordion title="A member sees an allGood permission error">
    The person's allGood role doesn't include the action. Ask an allGood admin to review their Campaigns permission.
  </Accordion>

  <Accordion title="Image uploads fail">
    In Claude, add `api.allgoodhq.app` to the domain allowlist. See the optional step above.
  </Accordion>
</AccordionGroup>

If you're still stuck, contact [allGood support](mailto:support@allgoodhq.com) and include the time of the call so we can find it in the MCP Usage log.

## Related articles

* [Marketo MCP: security, data, and governance](/use-cases/marketo-mcp/security-and-governance)
* [Using with Claude Desktop](/use-cases/marketo-mcp/claude-desktop)
* [Using with ChatGPT Desktop](/use-cases/marketo-mcp/chatgpt-desktop)
* [Marketo MCP FAQ](/use-cases/marketo-mcp/faq)
