Answers to common questions about connecting and using Scrut MCP.
FAQs
Which roles can use Scrut MCP?
Any Scrut user (admin, contributor, auditor) can connect Scrut MCP to their AI tool. Once connected, your AI assistant only sees what your existing Scrut role already lets you see. You don't need to configure separate MCP-specific permissions.
If you're a partner or auditor with access to more than one workspace, your AI tool can reach every workspace you're already assigned to, and you can switch between them within the same session.
What happens if my Scrut role changes after I've connected Scrut MCP?
Your new role applies automatically; No need to reconnect. Scrut MCP checks your user record and role on an ongoing basis, so a role change takes effect within a few minutes of being made in Scrut.
What happens if my Scrut account is deactivated?
Scrut MCP requests will fail if your Scrut account is deactivated. A deactivated user can't use Scrut MCP, just as they can't sign in to the Scrut platform.
Are there limits on how many people in my org can connect through Scrut MCP at the same time?
No. Each person connects with their own Scrut login, and there's no cap on how many users in your organization can connect or stay active at the same time.
Is there a logout timeframe for Scrut MCP connections?
There's no fixed logout timeframe. Scrut MCP uses short-lived access tokens that your AI tool refreshes silently in the background, so you stay connected without re-entering credentials. You remain connected until you disconnect Scrut MCP from your AI tool, your sign-in grant expires or is revoked, or your Scrut account is deactivated. If any of these happen, the tool will prompt you to sign in again.
Can I connect Scrut MCP to multiple AI tools at the same time?
Yes. Each AI tool gets its own independent sign-in. You can be connected to Claude, Cursor, and others simultaneously. Disconnecting one doesn't affect the others, and none of them affect your Scrut web session.
Can Scrut MCP change the status, owner, or assignment of an item?
No. You can change statuses, owners, and assignments only in Scrut. Scrut MCP can show you this information, but it cannot update it.
What can't Scrut MCP do?
Scrut MCP cannot:
Create or edit policies, controls, or tasks
Change statuses, owners, or assignments
Do user administration
Touch the vendor, risk, or people modules
See anything the signed-in user doesn't already have access to
Replace the Scrut platform itself
Will Scrut MCP work with locally hosted models like Llama?
Yes, as long as the application running the local model (e.g., Llama via Ollama) supports remote MCP servers with OAuth sign-in. However, response quality depends on the model’s tool-calling ability, so results may differ with smaller local models.
What can I use Scrut MCP to read?
Common use cases include frameworks, next audit dates, controls, policies, evidence, and continuous cloud tests, along with their status, owner, and mappings.
Can I upload evidence through Scrut MCP?
Yes. You can upload a file and attach it to an existing evidence item. Scrut tracks every upload in its audit log, the same way a human user's upload would be.
Is every action taken through the Claude MCP connector logged the same way as a human user's actions, for audit purposes?
Yes, all actions taken through Scrut MCP are logged the same way as a human user's actions. For example, if user "John" has uploaded an evidence file via MCP, Scrut will display this audit log: "John uploaded [evidence attachment name]."
Can Scrut MCP help answer compliance questionnaires?
Yes. It can pull answers from your approved answer library, or generate an answer from your knowledge base with complete references so you can verify the source.
Can Scrut MCP produce digests or status updates?
Yes, Scrut MCP can generate digests and status updates on demand, for example a summary of what's outstanding ahead of an audit.
Can Scrut MCP read the full text of my policies and evidence documents?
Yes. Use the document content tool to pull the full text of one specific policy or evidence document when you need to quote or verify it.
Can Scrut MCP delete or overwrite anything in my compliance program?
No. Scrut MCP can upload files and attach evidence, but it can't delete or overwrite anything that already exists in your compliance program.
Do I still need to review what Scrut MCP produces?
Yes. Scrut MCP provides a faster starting point for questionnaire responses, evidence filing, and status updates. It doesn't remove human review from evidence decisions or audit responses.
Are there rate limits on Scrut MCP requests?
No rate limits are enforced today, and you don't need to space out your prompts.
Does Scrut MCP need access to my cloud environment or codebase?
It depends on the access you already have in Scrut. If your Scrut role includes cloud test remediation, Scrut MCP can use that same access to reach the infrastructure-as-code to suggest a fix. If your role doesn't include it, your AI tool won't have that access either, regardless of what you ask it to do. Tasks like asking questions, drafting questionnaire answers, and filing evidence don't need cloud or codebase access.
Does Scrut MCP replace Scrut?
No. Scrut remains your system of record for your compliance program. Scrut MCP brings that context into the AI tools you already work in; it doesn't move your compliance program anywhere else.
Is Scrut MCP available on all plans?
Yes. It is available for all plans (Foundation, Growth, and Scale)
Is Scrut MCP self-serve, or does Scrut need to enable it for our organization?
You can do it yourself. For step-by-step instructions, see here.
Can I switch between workspaces without reconnecting Scrut MCP?
Yes. If you have access to multiple workspaces, for example as a partner or auditor, you can switch between them within a single MCP session. You don't need to disconnect and reconnect for each workspace you want to review.
Does Scrut MCP support multi-entity filtering?
Yes. If a workspace has multiple entities configured, you can ask your AI assistant to filter artifacts, such as evidence, controls, or policies, by entity within that workspace. Entity access still follows the permissions you already have in Scrut.
Reach out to support@scrut.io or contact your CSM for further assistance.