One connector URL. Every teammate signs in as themselves, and the server checks their role again on every single call, not just at login. A marketing teammate’s Claude sees campaigns and intelligence. A support teammate’s sees orders and tickets. Neither sees the other’s, even if you hand that same link to your whole team.
Store connector for Claude
Settings → Claude connector
mcp.charvax.com/yourstoreA preview of the control you’ll have. It goes real once role enforcement ships end-to-end (below).
On Claude Team or Enterprise, your admin can push the connector to everyone at once. It doesn’t matter. Each person signs in as themselves, and the store hands back only what their role already sees in the admin sidebar.
The scope is re-checked server-side on every tool call rather than cached at sign-in. Ask for anything outside the highlighted scope and the answer is a decline, not a guess.
The same connector, the same store, two different mornings. Marketing gets a grounded, ready-to-review draft. Support gets today’s shipping exceptions. And when the same person asks something Support was never allowed to see, the answer is a decline, not a partial peek.
The decline doesn’t dead-end, either. It lands in your store’s access-request inbox, the same place your in-admin Copilot’s out-of-scope asks go.
rahul · role: marketing
> Draft a win-back message for anyone who’s gone quiet.
◆ find_customer → 3 customers idle 45+ days
◆ draft_winback → 3 drafts, capped by the offer engine
Three drafts, sized to their segment. Nothing sends until your team hits send.
kavya · role: support
> Any shipping exceptions today?
◆ shipping_exceptions → 1 NDR, retry window closes 6pm
> What’s our best-performing segment this month?
◆ customer_segments → blocked — outside support’s scope
That’s outside what I can see from here. I’ve sent a request to your store owner.
Five read tools ship the moment you turn the connector on. The two write tools (a draft, a toggle) stay off until you flip the store-level switch, and even then nothing sends itself.
get_todays_numbersOrders, revenue and AOV, so far today.
find_customerLook up a customer and their order history.
low_on_stockVariants under their reorder threshold.
open_ticketsSupport tickets waiting on a reply.
shipping_exceptionsNDR, RTO and unserviceable-pincode alerts.
draft_winbackDrafts a win-back message; a human still sends it.
toggle_agentTurns a store agent on or off, within scope.
You turn it on, choose which roles may connect, and can revoke anyone instantly. Every teammate gets their own “Your connected Claude” card on their profile — connect, see your own scope, disconnect.
Who can connect
Write-actions offConnected Claudes · 2
IllustrativeAditi Rao
Manager · every dashboard — via Claude Desktop
Rahul Mehta
Coupons · Intelligence · Customers — via claude.ai
Whatever a role can’t see in the dashboard, their Claude can’t see either. It’s enforced the same way, not a separate rulebook.
Your profile
Your connected Claude
Rahul Mehta
Marketing · claude.ai
Your Claude can see
Whatever it reads, it never sees a customer’s phone number, address, payment details or IDs — the AI receives a name and business signals, and the tools simply don’t emit the rest.
Today, a role mostly changes what your sidebar shows rather than what the server allows. Shipping a real external connector on top of that would be a broken lock, not a feature. So this ships once, and only once, these are true:
This page is the plan we’re building to, not a claim we’re making today.
Every channel. Your own Claude wired in.
Claude Connector ships in Sovereign, alongside Multichannel and Marketplace SEO — launching as the role-enforcement work above lands.