TrustWorks MCP + Claude Setup Guide
Use this guide to connect Claude to your TrustWorks privacy management platform through the TrustWorks MCP connector. Once connected, Claude can query TrustWorks data and, depending on the permissions enabled in Claude, create or update records. Delete actions are not currently supported.
Current status
TrustWorks MCP is currently available in production as a supported beta. The core setup and available tools are live, but we are still refining the experience based on early customer feedback.
As this is a beta feature, customer feedback is especially helpful. If you run into issues, notice unexpected behaviour, or have suggestions for improving the connector experience, please share this with your TrustWorks contact or TrustWorks Support.
Some capabilities may change as the feature evolves. In particular, support for SSO-only TrustWorks login setups is not yet available, but we are working on extending support for these setups soon.
Before you start
- A TrustWorks account with access to the organisation you want Claude to use.
- Claude.ai access with custom connectors enabled for your account or workspace.
- Your TrustWorks organisation alias. This is the alias you use on the TrustWorks sign-in screen.
- The right TrustWorks role permissions for the data or records you want to access. Claude cannot access records beyond the permissions of the signed-in TrustWorks user.
💡 SSO-only limitation: the MCP connector currently uses a separate TrustWorks login flow. It is not yet compatible with setups where users can only log in through SSO, for example Okta-only login. We are working on extending support for these setups and expect this to be available soon.
Setup steps
1. Open Claude connector settings
In Claude, go to Settings, then Connectors. Click the plus button and choose Add custom connector.

2. Add the TrustWorks MCP connector
Enter a display name, then enter the connector URL exactly as shown below. Open Advanced settings, set the OAuth Client ID to claude , leave OAuth Client Secret blank, then click Add.
Connector URL: https://mcp.trustworks.io/mcp OAuth Client ID: claude OAuth Client Secret: leave blank

3. Connect the new connector
After adding it, select the TrustWorks MCP connector from the list and click Connect.

4. Sign in to TrustWorks
Claude will redirect you to TrustWorks. Enter your organisation alias, email, and password, then sign in.

5. Review tool permissions in Claude
After connecting, Claude will show available TrustWorks tools grouped by permission category. Review these settings carefully before using the connector.

Tool permissions and safety
Claude will show TrustWorks tools in separate permission groups, such as Read-only tools, Write/delete tools, and Other tools. The exact labels are controlled by Claude, and the exact list of available tools can vary by tenant and by the signed-in user's permissions in TrustWorks.
In the current TrustWorks MCP implementation, the tools shown under Claude's Write/delete category are write tools. This means they can create or update TrustWorks records. Delete actions are not currently supported.
| Permission group | What it means | Recommended customer action |
|---|---|---|
| Read-only tools | These tools only read data from TrustWorks. They do not create, update, or delete records. | Safe for querying TrustWorks data. Review the data access still matches the user role and internal policy. |
| Write/delete tools | Claude may group these tools under "Write/delete tools." In the current TrustWorks MCP implementation, these are write tools that can create or update TrustWorks records. Delete actions are not currently supported. | Proceed with caution. Keep these tools set to Needs approval unless your organisation has explicitly approved creating or updating TrustWorks records through Claude. |
| Other tools | These are tools that do not fit neatly into the read-only or write/delete categories. | Review the individual tool name and approval setting before allowing Claude to use it. |
💡 Important: enabling write tools introduces the possibility of TrustWorks data being modified through Claude. Customers should understand the impact of each tool before approving it and should keep approval controls enabled unless their organisation has explicitly approved automated changes.
How authentication and data access work
- The connector uses OAuth 2.0 Authorization Code with PKCE.
- No API key is required for Claude setup.
- Claude acts through the signed-in TrustWorks user.
- TrustWorks role permissions still apply. Claude does not bypass TrustWorks permissions.
- Tokens are not stored by the MCP server.
- Conversation data is not collected or stored by the connector.
What the connector can do today
- Read TrustWorks data, for example processing activities, risks, assets, assessments, data repositories, and AI use cases, depending on the tools available to your tenant.
- Create and update TrustWorks records through supported write tools, subject to Claude approval settings and the signed-in user permissions.
- Delete actions are not currently supported through the TrustWorks MCP connector.
- Work with Claude today. MCP is model-agnostic, so it may also work with other AI assistants that support the MCP standard.
Current limitations
- Completing survey-style assessments through the AI assistant is not currently supported.
- SSO-only setups are not yet compatible with the current MCP login flow. We are working on extending support for these setups soon.
- Delete actions are not currently supported.
- Available tools may vary by tenant and TrustWorks user permissions.
Test the connector
After setup, start a new Claude chat and ask a simple read-only question, for example:
Can you list my processing activities?
Claude should indicate that it used the TrustWorks MCP connector and return records that your TrustWorks user is allowed to access.
Troubleshooting
| Issue | What to check |
|---|---|
| Claude cannot add the connector | Confirm that custom connectors are enabled in Claude and that the URL is exactly https://mcp.trustworks.io/mcp . |
| The TrustWorks sign-in screen does not work | Confirm the organisation alias and credentials. If your organisation uses SSO-only login, please note the current MCP login flow is not yet compatible with SSO-only setups. |
| Claude cannot find expected data | Check that the signed-in TrustWorks user has access to the relevant records and that the relevant tools are available for your tenant. |
| Claude asks for approval before using tools | This is expected when the Claude permission setting is set to Needs approval. |
| Claude tries to use a write/delete tool unexpectedly | Do not approve the action unless you understand the impact. Review the tool permission category and your Claude approval settings. |
Support and feedback
TrustWorks MCP is currently available as a supported beta, and feedback is highly appreciated. If you have suggestions, notice unexpected behaviour, or think the connector could work better for your use case, please share this with your TrustWorks contact or TrustWorks Support.
If the connector does not work after the troubleshooting checks above, please contact TrustWorks Support and include:
- The connector URL used in Claude.
- The TrustWorks organisation alias used during sign-in.
- A screenshot of the error or unexpected behaviour.
- The action you were trying to perform in Claude.
- Whether your organisation uses SSO-only login.