How do I manage or revoke an AI assistant's access?

1 min readLast verified 2026-06-17

Every assistant you've connected lives under Connected apps in Settings → AI Access (MCP). From there you can disconnect one entirely, or block it from a single workspace while leaving the rest connected.

See what's connected

Go to Sidebar → Settings → AI Access and scroll to "Connected apps". Each row is one assistant you've signed in with, showing:

  • its name (Claude, Cursor, …),
  • whether it has Full access or is Read-only,
  • when it connected and when its access expires.

These are account-level — the same list appears no matter which workspace you opened the page from, because one connection covers them all.

Disconnect an assistant completely

  1. Find it under Connected apps

    Locate the assistant you want to cut off.

  2. Click Revoke

    Press Revoke and confirm. It loses access to all your workspaces immediately.

  3. It must sign in again to return

    Revoking is final for that session — the assistant has to complete the Decisa sign-in again to reconnect. Removing the app on the client side does not do this for you.

Block one workspace without disconnecting

Sometimes you want an assistant to keep working — just not in one sensitive workspace (say, a client account). You don't have to disconnect it.

  1. Expand the assistant

    Under "Connected apps", click Workspace access on that assistant. You'll see every workspace it can act on.

  2. Block the workspace

    Click Block next to a workspace and confirm. The assistant loses access to that one workspace immediately — its access to your other workspaces is untouched.

  3. Allow it again any time

    The blocked workspace stays in the list marked "Blocked". Click Allow to restore access whenever you want.

Blocking a workspace only affects that one assistant. It doesn't remove you from the workspace, doesn't touch your other connected apps, and doesn't change anyone else's access.

Which one should I use?

  • Lost or unknown device, or you're done with a toolRevoke the whole connection.
  • Trusted tool, but one workspace is off-limits to itBlock that workspace and leave the rest.

Access also ends on its own when a connection expires (shown on each row). An expired assistant simply has to sign in again — nothing was lost.