CatchCMS defines clear permission boundaries for admin users, frontend visitors and MCP clients. Site data is isolated by scope, while theme resources and admin operations follow system permission rules.
Let MCP follow admin permissions
An MCP token is associated with an admin account. Before an AI client queries or maintains content, it reads sites, categories, models and fields within that account's permission scope. This supports team-based website operations.
Manage token expiration and revocation
Teams can set an expiration period for each MCP access token and revoke it when needed. Multi-site operations, content collaboration and AI-assisted maintenance all have clear operational boundaries.