Skip to main content

What data can Claude or ChatGPT access through the SalesScreen MCP?

What the SalesScreen MCP can read and create, which personal data is involved, where it's processed and how to control access. For IT, security and privacy reviews.

Written by Marius Ekerholt

🙋 This article is for: Company Admins, IT, security and privacy teams reviewing the SalesScreen MCP before it's connected to Claude or ChatGPT.

⭐ Available on: Scale, Pro and Enterprise.

The short version

  • It only sees what the signed-in person can see. The assistant signs in with that person's SalesScreen login and gets the same access they have. Only Company Admins and Managers can connect it.

  • It can create some things, but not change or delete them. For example, it can start a competition, but it can't edit users, delete data or log activities.

  • SalesScreen never sees your conversation. We only receive the specific requests the assistant makes, such as "get this week's leaderboard for Team North".

  • SalesScreen data stays in the EU on our side. The MCP runs on the same Microsoft Azure setup as the rest of SalesScreen.

  • Every request is logged and the log is kept for 60 days.

  • Company Admins can switch it off for the whole company at any time.

What data the assistant can read

  • People and structure: first and last names, user IDs, and which teams and departments people belong to.

  • Performance: results and targets on your metrics, for people, teams, departments and the company.

  • Engagement: competitions, battles, missions, achievements, endorsements (including the comment written), feed posts and boards.

  • Setup: metric definitions and your activity types.

Which personal data is involved

Through the MCP, the assistant can access:

  • First and last name, and SalesScreen user ID

  • Team and department membership

  • Sales and activity results linked to each person, including targets

  • Participation in competitions, battles and missions, and achievements earned

  • Endorsements and feed posts, including the text written and who wrote them

The MCP does not return email addresses, phone numbers, birthdays, profile pictures or IP addresses.

Can the assistant change data in SalesScreen?

Yes, but only by creating new items. Everything it creates is created as the signed-in person, exactly as if they'd done it in SalesScreen themselves.

It can create:

  • Competitions, battles and missions

  • Endorsements (including coins, where the category allows it)

  • Feed posts

  • Boards and metrics

It can't:

  • Edit or delete existing competitions, battles, missions or other data

  • Log, change or delete activities or sales data

  • Add, change or remove users, teams, roles or settings

  • Touch rewards, coin balances or redemptions

How access works

  • Sign-in: each person signs in with their own SalesScreen login through a secure sign-in page (OAuth). The AI assistant never sees their password.

  • Permissions: the assistant gets exactly the access that person already has in SalesScreen — no more.

  • Who can connect: Company Admins and Managers only. Regular users can't.

  • Removing access: anyone can disconnect SalesScreen in their assistant's connector settings. Access stops straight away.

Where the data is processed

On the SalesScreen side: the MCP runs on the same Microsoft Azure infrastructure as SalesScreen, in the North Europe region (Ireland), with West Europe (Netherlands) as backup. All traffic is encrypted in transit. We log every MCP request and keep those logs for 60 days.

On the AI side: once SalesScreen sends an answer to Claude or ChatGPT, that data is handled by Anthropic or OpenAI under your organisation's agreement with them. That agreement decides things like where the data is stored, how long it's kept and whether it can be used for training. We recommend using a business plan (Claude Team or Enterprise, or ChatGPT Business or Enterprise) and checking its data settings before connecting.

How this fits with our Data Processing Agreement

SalesScreen processes your data as your processor under our Data Processing Agreement. Connecting an AI assistant is a choice your organisation makes, in the same way as connecting any other tool to SalesScreen. Anthropic and OpenAI are not SalesScreen sub-processors — they process the data on your behalf, under your own agreement with them.

Turn off MCP connections for your company

  1. Go to Manage → Settings → Scout AI, or open app.salesscreen.com/#/settings/scout.

  2. Switch off Allow MCP connections.

No one in your company can connect SalesScreen to an AI assistant while this is off.

What if this doesn't work?

We only want some managers to use it: the SalesScreen setting applies to the whole company. To limit who can use it, control it in your AI tool: on Claude Team or Enterprise, only organisation owners can add the connector. On ChatGPT Enterprise, admins can choose who gets access and which actions are allowed.

Our security team needs more documentation: ask your Customer Success Manager for our Security Overview. We're ISO 27001 certified, and summaries of our annual penetration tests are available on request.

We need to see what the assistant has done: everything it creates shows up in SalesScreen as created by the signed-in person, and every MCP request is kept in our audit log for 60 days.

Related articles

Did this answer your question?