xMatix
Sign in Request demo
xMatix
PRODUCTS
SalesField SalesCRMRewardsClaimsInventoryProcurementWarehouse ManagementField ServiceServiceSupportTelephony & MessagingFinance & AccountingPayrollExpense ManagementCommercePortalsAnalytics & ReportingData StudioMobile AppSee all products →
PLATFORM
Platform overviewApp BuilderAutomationIntegrationsSecurity & GovernanceChange ManagementDevelopers
SENSE AI
Sense AI overviewSense AssistSense ControlSense VisionAI StudioTrust & governanceIn Claude & ChatGPTUse cases
SOLUTIONS
FMCG & DistributionManufacturing & Dealer NetworksAutomotive & DealershipsPharma & HealthcareConsumer DurablesAgri-InputsBuilding MaterialsService NetworksWarehousing & 3PLFinancial AccountingERP SoftwareIndia GST ComplianceUAE VAT & e-InvoicingSaudi ZATCA & VATAll solutions →
RESOURCES
Knowledge CenterDeveloper & CLIBlogGuidesWhat is xMatix?Company facts
COMPANY
AboutCareersPartnersEventsContactAuthorsLegal
Sign in Request demo
GUIDES · IT EVALUATOR

Connecting Claude or ChatGPT to xMatix

A step-by-step guide for administrators and IT: enabling external assistants, connecting Claude, ChatGPT or Claude Code to your xMatix organisation, choosing the write ceiling, and what to check before you tell the company.

· Platform Engineering · · 9 min read

This guide is for the administrator who has been asked "can I use our data from Claude?" and wants to say yes without regretting it. It covers what to decide before you switch anything on, the switch itself, the connection steps in each assistant, and the checks that tell you it is working as governed rather than merely working.

Before you begin: three decisions

Who can connect. Anyone with a normal xMatix login in the organisation. There is no separate seat: the assistant reasons with its own model, so a connected assistant consumes none of the organisation's AI credits, and the tools it is offered follow the same Sense capability grants and licensing (reports, dashboards, knowledge) as the in-product assistant. Decide whether that is everyone or a pilot group, and tell the group.

Whether writes are allowed. The default is no. With writes off, every token the platform issues is capped at read-only regardless of what the assistant requests, and the write tools are not even listed. Most organisations should run read-only for the first weeks. Writes — creating and updating records and, for administrators, the setup tools — are a separate switch. When you do turn it on, remember that every write still runs under the user's own permissions, and that every setup tool is marked read-only or destructive, so a well-behaved assistant asks the administrator before it changes configuration.

Whether to restrict the assistants. By default any standards-compliant assistant may register. If your policy names the approved tools, add them to the approved-assistants list and everything else is refused at sign-in.

Step 1 — turn it on

In xMatix, open Setup → Sense AI Studio → External Assistants. The page shows the organisation's MCP endpoint URL — the one thing users will need — and counters for assistants, writes and active connections. Open Settings and switch on Allow external assistants. Leave Allow writes off for now. Add approved assistants if you decided to. Save.

Copy the endpoint URL. Nothing else on this page grants access a user does not already have; it decides only whether assistants may act as your users at all.

Step 2 — connect an assistant

Each assistant has its own settings path, but the flow is the same: paste the endpoint, sign in with your normal xMatix credentials in the window that opens, choose the organisation if you belong to more than one, and approve the requested scopes.

  • Claude (web or desktop): Customize → Connectors. If xMatix is listed in the connector directory, click Connect; otherwise choose Add custom connector and paste the endpoint URL. Either way Claude opens the xMatix sign-in.
  • ChatGPT: Settings → Connectors → Create, paste the same URL. The connector's search and fetch tools also make it usable in deep-research mode.
  • Claude Code: install the xMatix plugin — /plugin marketplace add xMatixAI/claude-plugin, then /plugin install xmatix@xmatix (sandbox organisations: xmatix-sandbox@xmatix) — and /mcp signs you in; the browser returns you to the terminal. Without the plugin, add the endpoint as an HTTP MCP server: claude mcp add --transport http xmatix <endpoint URL>.

The consent screen you see is rendered by xMatix, not by the assistant. It names the client, lets you tick the organisations the assistant may reach (and pick the default when you belong to several), and shows the scopes that will actually be granted after your organisation's ceiling is applied. If writes are off, it will not offer a write scope.

Step 3 — the first questions

Ask the assistant who it is acting as. The connector's identity tool returns the user, the organisation and the effective scopes; if the answer is not you and your organisation with read scopes only, stop and check the consent you approved.

Then ask something you know the answer to. "How many open sales orders do we have?" "List the distributors in the west region." "Run the monthly collections report." Watch what the assistant does: it should list the entities, describe the one it needs, then query — and cite the records it used. Aggregations should come back as charts where a chart makes sense.

Finally, ask something you are not allowed to see. Pick a record your own profile cannot open and ask for it by name. The assistant should report that it is not accessible, because the query ran as you and the platform's record security refused it. This is the check that tells you the connector is governed and not merely connected.

Step 4 — what the administrator sees

Back on the External Assistants page, the connection now appears in the list: which assistant, which user, what access, when connected and last used. Each row has a Disconnect. Every tool call the assistant makes is written to the audit trail as the user, and setup calls appear in the setup audit trail exactly as if the administrator had used the Setup screens. There is no separate log to go looking for.

Step 5 — rolling it out

Tell users three things. Which URL to paste. That they sign in as themselves and the assistant sees only what they can already see. And that the organisation has decided, for now, that assistants can read but not write. A one-paragraph note covers it; the connector needs no client software and no per-user configuration beyond the sign-in.

When you decide to allow writes, switch it on in Settings. Users do not need to reconnect: the policy is re-evaluated every time a token is refreshed and on every call, so the new ceiling applies to existing connections. The same is true in the other direction — switching the feature off ends every session immediately.

What the connector does not do

It does not train any model on your data; the platform never does. It does not widen access: the token's scopes, the organisation's capability grants and the user's permissions each narrow what the previous layer allowed. It does not offer tools a Sense agent could not be granted in AI Studio. It does not survive a policy change: off means off, now. What the assistant provider does with the content of a conversation is governed by your agreement with that provider, exactly as it is today when someone pastes a spreadsheet into it — the difference is that the data now arrives permission-checked, cited and audited.

Troubleshooting

  • The assistant cannot find an authorization server. The feature is off for the organisation, or the assistant is not on the approved list. Check Settings.
  • Sign-in works but the organisation is not offered. That organisation has not enabled external assistants, or its policy refuses this client; the consent screen counts such organisations so the user knows to ask their administrator.
  • No write tools appear. Writes are off for the organisation, or the organisation is in read-only mode. Both are intended.
  • A question returns "not accessible". The user's own permissions refused it. Check the user's profile in xMatix, not the connector.
  • The connection stopped working. An administrator disconnected it or switched the feature off. Reconnect once the policy allows it.

The developer documentation lists every tool and the protocol details; the product page states the guarantees in plain terms for an evaluator.

Related: Sense in Claude and ChatGPT · One sign-in for every assistant · Rolling out an AI assistant your CISO will sign off

← All guides
See it on your business.
Request a demo