The Qoren platform MCP

Every Qoren agent gets a tool server for the platform itself. See the tool groups, what is on by default, which tools ask for approval, and how to switch them.

On this page

Every agent Qoren deploys gets one extra tool server: Qoren itself. Through it an agent can look itself up, message the agents beside it, hand you a file as a link, read your usage, and even operate your environments and agents. Only looking at itself is on until you switch more on, and the environment an agent runs on sets the most it can ever be given.

What the platform MCP is#

MCP (Model Context Protocol) is the standard way AI agents discover and call tools. The platform MCP is an MCP server that Qoren runs for you. It is not something installed on your environment, and it is the same server for every runtime: OpenClaw, Hermes and Codex agents all reach it the same way.

  • Each agent has its own credential. Qoren gives every agent a token for this server when it sets the agent up, and writes it into the agent's configuration by reference, so the value does not sit in a config file you might share.
  • An agent only sees the tools you allowed. A tool you switched off is not refused, it is not offered at all, so the agent never plans around something it cannot do.
  • Changes apply at once. The server checks your settings on every call, so a switch you flip takes effect on the agent's next tool call, and a tool you switch on is offered the next time the agent refreshes its tool list. Nothing needs to restart. The one exception is Mail: switching it reconfigures the agent to attach or detach its mailbox.
  • Secret values never come back. Tools that touch configuration or the vault return secret names only.

The tool groups#

Tools come in groups. Switching a group on turns on all its tools; you can then switch single tools off inside it.

GroupWhat the agent can doOn by default
ItselfRead its own identity, environment, configuration, logs and telemetry, post a status line, and read the platform guides for the groups it hasAlways on
TeammatesDiscover the other agents on the same environment and send them messagesOff
MailAdds no tools. Attaches the agent's mailbox so it can read and send emailOff (see below)
FleetInspect and operate your environments, agents, jobs and templates. Destructive actions ask a person firstOff
AccountRead usage, spending and plan limits. Never billing details or secret valuesOff
Public linksPublish a file from its own workspace as an expiring link, instead of pasting the contentsOff
ProposalsRead and write your client proposals, with live pricing. Deleting one asks a person firstOff
LeadsRead and work on your agency's leads: add them, update them, add notes and log touches. Deleting one asks a person firstOff
ClientsRead and manage your clients. Archiving one asks a person firstOff
IntegrationsUse the tools you connected, such as Pipedrive or GitHub, through curated actions, only on the connections you gave this agent access toOn, but offers nothing until you give the agent access to a connection

Proposals, Leads and Clients hold your agency's own records, so they have one more limit on top of the switches below: what the account owner allows agents to do in Settings, Team (see what your agents can do). Until the owner allows something there, these tools are not offered to any agent.

Mail only matters for an agent that has its own mailbox; see agent email for how an agent gets one.

A new environment allows only Itself, plus Integrations: that group is on for every environment that never switched it, because it offers nothing until you give an agent access to a connection, which is a separate choice on the Integrations page. Switch it off on the environment or the agent to close it anyway. A new agent starts with what its template allows, or only Itself (and Integrations) when the template sets nothing. The Work with teammates switch in an agent's permissions is the same thing as the Teammates group on its environment: see agents working together.

Itself#

ToolWhat it does
Who am IReturn this agent's name, runtime, model, template and current state
My environmentReturn the environment it runs on: size, region, status and the peers on it
My configurationReturn its scheduled tasks, MCP servers, chat channels and the names of its secrets. Values are never returned
My logsRead a slice of its recent runtime log
My telemetryRead its recent activity and resource telemetry
Report my statusPost a short status line, with optional progress, that the console shows on the agent
Read a platform guideRead the detailed guide for a group it has, or list the guides it may read

When your account uses Qoren's scheduler for scheduled tasks, Itself also holds five scheduling tools: My scheduled tasks, My scheduled task runs, Schedule a task, Change a scheduled task and Delete a scheduled task. They let the agent manage its own scheduled tasks when you ask it to do something regularly.

Teammates#

ToolWhat it does
List teammatesList the other agents on this environment that can be messaged
Message a teammateSend a message to another agent on the same environment

Fleet#

ToolWhat it doesAsks for approval
List environmentsList your environments with their size, region and statusNo
Get an environmentRead one environment in detail, including the agents on itNo
List agentsList your agents across every environmentNo
Get an agentRead one agent in detail: runtime, model, template, state and configurationNo
List jobsList recent jobs and their statusNo
Get a jobRead one job in detail, including its events and any failure reasonNo
List secret namesList the names of your vault secrets. Values are never returnedNo
List templatesList your agent templatesNo
Get a templateRead one agent template in detailNo
Create an environmentCreate a new environment on your planNo
Create an agentDeploy a new agent from a template onto an environmentNo
Configure an agentChange another agent's model. An agent cannot reconfigure itselfNo
Message an agentSend a message to another agent on its own environment. Agents on other environments are refused. A Custom agent, which has no environment, may message any agent on your accountNo
Cancel a jobCancel a queued or running jobNo
Destroy an environmentTear down an environment and everything on itYes
Destroy an agentRemove an agent from its environmentYes
Resize an environmentMove an environment to a different size, which restarts itYes
Reprovision an agentReset an agent to its template on the same environment, discarding its customizationsYes
Move an agentMove an agent to a different environmentYes

Anything the agent creates counts against your plan exactly as if you had created it, and uses your credits the same way.

An agent that works for one of your clients (assigned to a client, or running on a client's environment) is never offered the Fleet or Account tools, whatever its switches say. Both reach across your whole account, and a client's agent stays inside that client's work.

Account#

ToolWhat it does
Account usageRead the account's usage for the current period
Account spendingRead the account's recorded spending for the current period
Plan entitlementsRead what your plan allows, such as environment and agent limits
ToolWhat it does
Share a file publiclyPublish one file from its workspace as an expiring public link
List shared filesList the links it has published, with their status and how often they were opened
Revoke a shared linkSwitch off a link so it stops working immediately

A link opens a page that shows the file and offers a download, to anyone who has it, until it expires or is revoked. Only files in the agent's workspace/ folder can be shared, up to 4 MB each, for at most 30 days. You can publish and revoke the same links from a terminal with qoren agent share (see the CLI command reference).

Proposals#

ToolWhat it does
List proposalsList your proposals with their client, status and monthly price
Read a proposalRead one proposal in full: its agents, pricing settings and document text, with its live quote
Price a changePrice a change to a proposal, or a new one, without saving it
Create a proposalStart a draft proposal, optionally for one of your clients
Change a proposalChange a proposal's agents, pricing settings or document text
Set a proposal's statusMark a proposal as draft, sent, accepted or declined
Assign a proposal to a clientAssign a proposal to one of your clients, or to none
Delete a proposalDelete a proposal for good. Asks for approval

The agent works on the same proposals you see on the Proposals page, priced the same way: from the live rate card, at your margin, with model spend ranges quoted as ranges. The prices follow from the agents, their usage and your pricing settings; like you, the agent can also type an agent's monthly price by hand. A proposal an agent creates is a draft on your list like any other; the account log records which agent made each change.

The group only works on an account that has proposals. On an account without it, the tools are not offered even when the group is on. Each tool also needs the matching permission in the account's agent ceiling: listing, reading and pricing need View, creating needs Add, changing, setting the status and assigning a client need Edit, and deleting needs Delete.

Leads#

ToolWhat it doesPermissionAsks for approval
List leadsList your leads, optionally filtered by stage, warm or cold, or a search termViewNo
Read a leadRead one lead in full, with its recent history and logged touchesViewNo
Add a leadAdd a lead with a name and, optionally, contact details, stage, needs, deal value and next stepAddNo
Change a leadChange a lead's details, stage, deal value or next stepEditNo
Add a note to a leadAdd a note to a lead's historyEditNo
Log a touchRecord an email or a message on Reddit, LinkedIn or X, sent or received, as done or plannedEditNo
Delete a leadDelete a lead for goodDeleteYes

These are the leads on your account's Leads page. An agent only records what happened: logging a touch never sends an email or a message. Changes an agent makes show in the lead's history as made by Agent. The group only works on an account where Leads is switched on, which also needs Clients.

Clients#

ToolWhat it doesPermissionAsks for approval
List clientsList your clientsViewNo
Read a clientRead one client in detailViewNo
Add a clientAdd a new clientAddNo
Change a clientChange a client's detailsEditNo
Archive a clientArchive a client, hiding it from the Clients page and the client menusDeleteYes

The group only works on an account that has Clients.

Integrations#

ToolWhat it does
List my integrationsList the connected tools this agent may use: each connection's tool, account, level, tool names and events, and the triggers it asked for. Never a key
Ask for a triggerAsk to be woken when an event happens in a connected tool. The trigger waits for the account owner to approve it, whatever the agent's autonomy, and an agent can have at most 5 of its own
Remove my triggerRemove a trigger this agent asked for, waiting or live. It cannot remove yours

Next to these, the agent gets the curated tools of every connection it has access to, such as Find a deal or Add a note for Pipedrive, filtered by its level and by the tools you ticked for it. Which tools each tool offers, and which always ask, is in each tool's guide. Every call is checked again on Qoren's side: the agent's access, its level, the hourly read limit, and whether it must wait for approval. See how Qoren keeps connected tools safe.

Unlike Fleet and Account, this group also works for an agent that works for one of your clients, but only with that client's own connections.

The account ceiling for leads, clients and proposals#

The account owner decides, once for the whole account, the most any agent may do with leads, clients and proposals. It is the Agents section of Settings, Team: a grid with a row for each of the three and a column each for View, Add, Edit and Delete. See choose what your agents can do.

  • It starts empty. Until the owner ticks something there, no agent gets any of these tools, whatever its environment and its own settings allow.
  • The other switches narrow it. An environment's Platform access and an agent's Qoren tools still decide which of the allowed tools each agent gets, as for every other group. They can only take away from the ceiling. A tool outside it shows Not allowed for agents in this account. The owner can change it in Settings > Team.
  • Agents working for a client never get these tools. An agent assigned to a client, or running on an environment that belongs to a client, is refused every leads, clients and proposals tool, whatever the ceiling says. Its panels show Agents working for a client never get this. Your clients never see your agency's own records.

Set the ceiling on an environment#

The environment decides the most any agent on it may do. An agent's own settings can only narrow that, never widen it.

  1. In the sidebar, click Environments and open the environment.
  2. Open the Settings tab. The Platform access card lists every group.
  3. Switch a group on to allow all its tools, or open it with the arrow and switch single tools off (1).
The Fleet group expanded in an environment's Platform access card: every fleet tool has its own switch, and the destructive ones carry an Asks for approval tag.12
The Fleet group opened in an environment's Platform access card. Tools that ask a person first are tagged.

Tools tagged Asks for approval (2) never act on their own; see below.

Choose the Qoren tools for one agent#

  1. Open the agent and click Settings, then Permissions.
  2. Under Qoren tools, Itself is marked Always on (1).
  3. Switch a group off to take it away from this agent (2), or open the group and switch single tools off.
  4. A group marked Disabled by environment (3) is closed on the environment, so it cannot be switched on here. Change it on the environment first.
The Permissions section of an agent's settings: Work with teammates, the Qoren tools list of capability groups with their switches, and the Access token row with Rotate platform token.1234
The Permissions section of an agent's settings, with its Qoren tools and access token.

For everything else in this section, see agent permissions.

Set the starting tools in a template#

A template carries a default that new agents start with. In the template editor, open MCP servers and use Qoren platform access. It is a starting point, not a ceiling: the environment still decides the maximum, and you can narrow each agent afterwards. An agent that creates another agent with Create an agent cannot choose its access; the new agent gets the template's default.

Replace an agent's token#

Under Access token, click Rotate platform token (4), then Rotate. The old token stops working at once, and the agent picks up the new one when its configuration is rewritten. Use this if you think the token leaked, or to cut an agent off immediately.

Approvals, logs and limits#

  • Destructive tools ask a person. When an agent calls a tool tagged Asks for approval, nothing happens yet: the request goes onto the Approvals page and the agent is told it is waiting. Approving runs the action as you, with your plan checked at that moment; a request nobody decides expires after 24 hours. To approve deleting a proposal or a lead, or archiving a client, you need the matching Delete permission yourself.
  • An agent's autonomy covers these tools too. Its Qoren actions rows in Autonomy decide which kinds of call wait: spending money and changing the fleet, scheduling its own tasks, messaging other agents, sharing public links, and editing leads, clients and proposals. A call in a kind set to Ask first waits on the Approvals page with the exact arguments the agent sent, wherever the turn came from. Posting a status line and revoking a public link always go ahead. Changes through connected tools follow the same rows: see actions that always ask and other changes follow the agent's autonomy. Approving runs that exact call once, as the agent, with every check made again at that moment, and the log names you as the approver. Asking twice for the same thing makes one request, and an agent can have at most 10 waiting.
  • Every change is logged. Each tool call that changes something is recorded in your account log as done by that agent. Reads are not recorded, except calls to connected tools, where every call is.
  • Calls are rate limited. Each agent can make 60 platform calls a minute. Past that, calls are refused until the minute is up.
  • A refused call says why. When a call is refused, for the rate limit, a missing permission or a bad argument, the agent gets the reason as the tool's answer, so it can correct itself or tell you.
  • Agents cannot change access. No tool reads or changes these settings, so an agent can neither widen its own access nor see what another agent may do.

The platform guides (qoren-* skills)#

The detailed "how to use these tools" guidance is not stuffed into every prompt. It ships as one guide per group, read only when needed: qoren-self, qoren-teammates, qoren-mail, qoren-fleet, qoren-account, qoren-public-links, qoren-proposals and qoren-integrations.

  • On a runtime that reads a skills folder (Hermes today), the guides for the groups the agent has are placed there as skills, and removed again when you switch a group off.
  • On every runtime, the agent can read the same guides with the Read a platform guide tool.

An agent only ever sees guides for groups it can use. The qoren- name prefix is reserved, so your own skills cannot use it.

Frequently asked questions#

What can a brand new agent do?

Read itself, and use the connected tools you gave it access to, and nothing more, unless its template or its environment says otherwise. Teammates, Mail, Fleet, Account and Public links are all off until you switch them on for the environment. Proposals, Leads and Clients also need the account owner to allow them for agents in Settings, Team.

Can an agent working for one of my clients read my leads or proposals?

No. An agent assigned to a client, or on an environment that belongs to a client, never gets the leads, clients or proposals tools, whatever any switch says.

Can an agent give itself more access?

No. No tool reads or changes access settings, so an agent cannot widen or even inspect its own access. Only a person in the console can change it.

Can an agent read my secrets?

No. Tools that touch configuration or the vault return secret names only. No tool returns a secret value, on any plan, at any setting.

What happens when an agent asks to destroy something?

The call is parked as a request on the Approvals page, and the tool tells the agent that nothing has changed yet. If a person approves, the action runs as them. A request nobody decides expires after 24 hours.

How do I cut an agent off right now?

Switch its groups off, which applies on its next call, or click Rotate platform token so the token it holds stops working at once.

Was this page helpful?

Last updated