# Check the workspace boundary of an MCP connection

Illustrative planning brief; no automatic product import.

Illustrative case: an operator copies a working client setup but needs a different workspace for the current request.

## Decision

Verify the approved auth mode and organization binding before reading workspace tasks.

## Owned work

- Identify the deployed mode
  - Owner role: Operator
  - Acceptance evidence: API-token versus session-token behavior is confirmed for the endpoint.
- Establish organization context
  - Owner role: Operator
  - Acceptance evidence: Token-bound organization or session header matches the intended membership.
- Check the first read
  - Owner role: User
  - Acceptance evidence: A bounded read returns evidence from the expected workspace.

## Workflow

1. Ask the product operator for the deployed auth-mode contract.
2. Use its organization-binding mechanism without borrowing another account.
3. Stop on membership failure and clarify context rather than bypassing it.

## Judgment

API-token mode derives organization from introspection; session mode uses its organization header. A landing page does not verify either deployment configuration.


## Filled illustrative decision

The fictional setup review finds that copied configuration still binds a different organization. The operator pauses task retrieval and establishes the intended auth context first. No real token or organization identifier is shown, and this planning decision does not prove the remote session is connected.


## Scope conditions

- Auth mode / Operator confirms the deployed contract / Do not infer mode from a copied example
- Organization / Correct token claim or session header and membership / Clarify any mismatch
- First read / Expected workspace evidence / Stop before expanding tool use


## Workflow questions

### Should both modes use the same organization header?

No. The source paths bind organization differently; follow the deployed mode.

### Can I switch accounts to fix an access error?

Do not substitute another account or workspace without the user’s intended scope.

## Product connection

Verify the TeamBoost MCP server’s workspace context before reading or changing the records discussed in this guide.

Confirm account availability before adopting this manual outline.
