Skip to main content
Use this guide to connect a managed application or an MCP server, verify what Cromo can access, and make the connection available to the correct Project.

Choose the connection type

A managed integration normally feeds external content into Sources. An MCP connection can also expose operations that read or change another system.
Connect a work account created for the intended process. Do not authorize a personal account or broader permissions than the Project needs.

Before you begin

You need the Admin or Owner role and membership in the target Project. Prepare:
  • the external account or MCP credential;
  • the exact files, folders, channels, repositories, or mail filters to include;
  • an owner responsible for access reviews and credential rotation;
  • a safe read-only test;
  • one reversible write test if the connection must change external data.

Open Connectors

  1. Open the Project that will use the connection.
  2. Select Settings in the Project sidebar.
  3. Under Project, select Connectors.
  4. Choose Integrations or MCP.
The selected Project matters: configure and test the connection from the same Project that will use its content or operations.

Connect a managed application

1. Select the provider

Open the Integrations tab. Search by name or find the provider in Available Integrations, then select Connect.
Cromo Project settings showing the Integrations catalog with Google Workspace, Gmail, Notion, OneDrive, OneNote, Outlook, Slack, and GitHub

The Integrations tab lists managed applications and the action used to connect each one.

2. Authorize the intended account

Complete the provider’s authorization flow. Before approving access, verify:
  • the account name and email;
  • the Workspace or tenant shown by the provider;
  • the permissions requested;
  • whether the account owns or can read the intended resources.
Return to Cromo after authorization completes.

3. Select content and synchronization

Choose only the content that belongs in the Project. Depending on the application, this can include files, folders, pages, channels, repositories, or filtered email. Then configure synchronization:
  • use a narrow folder, channel, repository, or mailbox filter;
  • exclude drafts, personal material, and unrelated departments;
  • choose a cadence appropriate to how often the source changes;
  • keep the external owner responsible for deleting or moving source content.
Start with one representative resource. Verify its content and citations before widening the selection.

4. Verify imported content

Open Knowledge → Sources and locate the synchronized item. Check:
  1. the Origin identifies the expected application;
  2. processing reaches Completed or presents a review item;
  3. the Source preview matches the current external content;
  4. important Knowledge facts preserve links to their evidence;
  5. a cited question in Chat returns the expected answer.
For the full verification flow, see Add and manage Sources.

Connect an MCP server

1. Browse or add a server

Open the MCP tab. Use search to find a catalog entry, or select Add custom MCP for a private or custom server. Catalog badges identify how an entry is reached. For a custom connection, use a Streamable HTTP endpoint available to Cromo.
Cromo MCP catalog showing search, catalog cards, transport badges, Connect actions, and Add custom MCP

The MCP tab provides a searchable catalog and the Add custom MCP action.

2. Enter the custom connection

In Add custom MCP, provide:
  • Name — a recognizable operational name, such as CRM — read only;
  • Server URL — the Streamable HTTP endpoint;
  • AuthenticationNone, Bearer token, or Custom headers;
  • Hide tools behind search — enable this when the server exposes many tools;
  • any required credential or header values.
Secret values are encrypted at rest and are not displayed again after saving. Keep the original credential in your secret manager.

3. Test before saving

Select Test connection. A successful network test proves that Cromo can reach and authenticate to the server; it does not prove every operation is safe. After saving, inspect the discovered Tools, Resources, and Prompts. Confirm that their names and descriptions match the server you intended to connect.

4. Run a least-privilege test

Test in this order:
  1. list or inspect a harmless resource;
  2. read one known record;
  3. compare the response with the source system;
  4. if writes are required, create or update a disposable test record;
  5. confirm the exact external change;
  6. remove the test record if appropriate.
A good first prompt is:
Only add write-capable credentials after the read path and field mapping are correct.

Control Project access

A connection is an operational permission. Workspace Admins and Owners control whether each Project has no access, read-only access, or full access to it. Use:
  • No access when the Project has no business need for the system;
  • Read only for research, verification, and reporting;
  • Full access only when a tested process must create or change external records.
Members can use approved connections. Admins and Owners manage their configuration.

Example: synchronize a renewal-policy folder

  1. Open Project settings → Connectors → Integrations.
  2. Connect Google Workspace with the operations service account.
  3. Select only the approved Renewal Policies folder.
  4. Enable synchronization.
  5. Open Knowledge → Sources and verify the imported policy.
  6. Resolve any Knowledge review item.
  7. Ask:
For a €150,000 renewal with a liability exception, identify the preparation steps and required approver. Cite the synchronized policy.
  1. Open the citation and compare it with the Drive file.

Troubleshooting

Authorization opens the wrong account

Cancel the provider flow, sign out of the unintended provider account, and reconnect. Verify the account identity before approving access.

The connection succeeds but no Source appears

Return to the integration and confirm that at least one supported resource is selected. Check folder, channel, repository, or mail filters, then review Knowledge → Sources again.

A synchronized Source is outdated

Confirm the external item still exists in the selected scope and that synchronization is enabled. If the owner moved or renamed it, update the resource selection.

Test connection fails for a custom MCP

Check the full HTTPS URL, authentication method, token, and custom-header names. Confirm that the endpoint serves Streamable HTTP and is reachable outside your private computer.

Tools are connected but Cromo chooses the wrong one

Improve the server’s tool names and descriptions. Enable Hide tools behind search when the server exposes many tools, then use a prompt that names the intended system and operation.

A Member cannot use the connection

Confirm that the person belongs to the Project, has at least the Member role, and that the Project has read-only or full access to the connection.

Connection review checklist

  • The credential belongs to the intended work account.
  • The selected content belongs in this Project.
  • Access is read only unless writes are required.
  • A known read returned the expected result.
  • Any write test used a disposable or reversible record.
  • Synchronized Sources and citations were inspected.
  • Credential ownership and rotation are documented.
  • Project access is reviewed when membership or responsibilities change.