Access
Every Access tool, with the scope it needs, its arguments and the API operation it calls.
14 tools
List access audit events
Read onlyatlas_access_audit_events_list
Read recent Access audit events, newest first, one page at a time. Returns { items, nextCursor } of grant, revoke, invite, module, suite, and seat events; pass nextCursor back as cursor for the next page, or filter with before.
- Scope
workspace:read- Calls
- Example prompt
- Show the last 25 access changes before midnight UTC.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
limit | integer | No | How many rows to return, 1 to 100. Defaults to 50. |
before | string (date-time) | No | Only events before this moment (ISO 8601). |
cursor | string | No | The nextCursor of the previous page. Leave it out for the first page. |
order | "asc" | "desc" | No | asc or desc. Newest first (desc) by default. |
Get access catalog
Read onlyatlas_access_catalog_get
Read the merged Access module catalog and suite definitions for the calling tenant. Read-only.
- Scope
workspace:read- Calls
- Example prompt
- Which Atlas modules and suites are available for this workspace?
Arguments
This tool takes no arguments.
Accept access invites
Changes dataatlas_access_invites_accept
Accept a workspace invite token as the calling user and return the created member id. The invite must be addressed to the caller's email; Atlas never enrols a different user.
- Scope
workspace:manage- Calls
- Example prompt
- Accept this workspace invite token for user usr_123.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes | Raw invite token from the invite link. |
name | string | No | Display name for the new member. |
Revoke access invites
Destructiveatlas_access_invites_revoke
Workspace admin action. Revoke a pending invite by id. Already accepted or revoked invites are treated idempotently.
- Scope
workspace:manage- Calls
- Example prompt
- Revoke invite inv_123 before it is accepted.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
inviteId | string | Yes |
Revoke access member grants
Destructiveatlas_access_member_grants_revoke
Workspace admin action. Revoke one member module grant. Existing revoked/missing grants remain idempotent.
- Scope
workspace:manage- Calls
- Example prompt
- Remove mem_123 access to PDF Studio.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
memberId | string | Yes | |
moduleId | "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | Yes |
Set access member grants
Changes dataatlas_access_member_grants_set
Workspace admin action. Upsert module permissions for a member and return the refreshed member projection.
- Scope
workspace:manage- Calls
- Example prompt
- Grant mem_123 view and export on Reports.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
memberId | string | Yes | |
moduleId | "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | Yes | |
permissions | array of "view" | "create" | "update" | "delete" | "export" | "admin" | Yes |
Update access member roles
Changes dataatlas_access_member_roles_update
Workspace admin action. Update a member role to admin, member, viewer, or guest and return the refreshed member projection.
- Scope
workspace:manage- Calls
- Example prompt
- Make member mem_123 a viewer.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
memberId | string | Yes | |
role | "admin" | "member" | "viewer" | "guest" | Yes |
Invite access members
Changes dataatlas_access_members_invite
Workspace admin action. Create a member invite with role and optional initial module grants. Returns the invite token once.
- Scope
workspace:manage- Calls
- Example prompt
- Invite sam@example.com as a viewer with Tasks and Team access.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
email | string (email) | Yes | |
role | "admin" | "member" | "viewer" | "guest" | No | |
modules | array of "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | No |
Remove access members
Destructiveatlas_access_members_remove
Workspace admin action. Remove a member from the workspace. The API prevents admins from removing themselves.
- Scope
workspace:manage- Calls
- Example prompt
- Remove mem_123 from this workspace.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
memberId | string | Yes |
Disable access modules
Changes dataatlas_access_modules_disable
Workspace admin action. Disable one Access module for the tenant. Idempotent server-side and audit-stamped.
- Scope
workspace:manage- Calls
- Example prompt
- Disable PDF Studio for this workspace.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
moduleId | "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | Yes |
Enable access modules
Changes dataatlas_access_modules_enable
Workspace admin action. Enable one Access module for the tenant. Idempotent server-side and audit-stamped.
- Scope
workspace:manage- Calls
- Example prompt
- Enable the Reports module for this workspace.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
moduleId | "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | Yes |
Get access snapshot
Read onlyatlas_access_snapshot_get
Read workspace access posture: suite, enabled modules, seats, members, member roles, and active module grants. Read-only.
- Scope
workspace:read- Calls
- Example prompt
- Show the current access snapshot for this workspace.
Arguments
This tool takes no arguments.
Update access suite
Changes dataatlas_access_suite_update
Workspace admin action. Change the workspace suite between personal and professional and return the refreshed access snapshot.
- Scope
workspace:manage- Calls
- Example prompt
- Move this workspace to the professional suite.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
suite | "personal" | "professional" | Yes |
Provision access workspace
Changes dataatlas_access_workspace_provision
Workspace admin action. Provision the initial workspace access posture, enabled modules, and admin membership, then return the access snapshot.
- Scope
workspace:manage- Calls
- Example prompt
- Provision Atlas Ops as a professional workspace with Tasks and Team enabled.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
workspaceName | string | Yes | |
suite | "personal" | "professional" | Yes | |
modules | array of "tasks" | "projects" | "board" | "calendar" | "inbox" | "focus" | "habits" | "goals" | "crm" | "contracts" | "client-onboarding" | "incident-management" | "esign" | "pdf-studio" | "meetings" | "time-tracking" | "workload" | "forecast" | "blog" | "ai-assistant" | "mcp" | "api" | "webhooks" | "automations" | "integrations" | "analytics" | "reports" | "audit-log" | "sso" | "two-factor" | "team" | "billing" | "themes" | No | |
adminEmail | string (email) | Yes | |
adminName | string | Yes |