# What can the agent access?

> A Competitor Tracker & Co. market report on how SaaS companies are turning AI-agent access into a buying question: data, actions, permissions and packaging.


A buyer used to ask a simple question: does this product connect to the tools we already use?

That question is getting sharper.

Now the buyer wants to know what an AI agent can safely reach. Can Claude query the finance model? Can ChatGPT read HR context? Can Cursor pull product feedback? Can Copilot answer questions from invoices, docs or analytics data? Can the agent only read, or can it update the record too?

That is the useful shift in the data. MCP is the visible protocol in many of the changes, but the protocol is not the buyer story. The buyer story is access: data, actions, permissions and plan limits.

Over the last 90 days, Competitor Tracker scanned 2,828 competitors and found 50,693 public website changes. After removing short-lived promo noise, 45,109 durable changes remained. Integration, API and related access changes accounted for 6,748 changes across 1,375 companies.

Inside that wider movement, we found 1,349 explicit MCP records across 436 companies. The durable changes fell into four practical buckets:

- **Data opened to agents:** vendors are telling buyers which business data an assistant can reach.
- **Actions added to access:** some agents can create, update, triage, route or trigger work.
- **Permissions pulled forward:** OAuth, RBAC, inherited permissions, approvals, audit trails and governance are becoming part of the sales story.
- **Agent access packaged:** MCP and agent access are showing up in pricing rows, plan limits, credits, bundles and navigation.

Those are different moves. They point in the same direction: integrations are becoming a question of controlled agent access.

## 1. Data opened to agents

This is the cleanest signal.

A vendor used to say, “we integrate with your stack.” Now the stronger page says, “your agent can use this specific business data.” That is much more useful for a buyer.

The buyer does not wake up wanting MCP. They want the agent to answer a real question with data the company trusts.

| Company | Category | What changed | Read |
| --- | --- | --- | --- |
| [Pendo Analytics](/companies/pendo/) | Product analytics | Added a section positioning AI as a core analytics capability, with Leo conversational analytics and an MCP server to query product data inside external AI tools. | Product teams are being sold on external AI asking questions of usage data. |
| Billtrust | Accounts receivable | Launched an MCP server integration for live invoice-to-cash data access via Claude and Microsoft Copilot. | Finance buyers can picture the job: query AR data through an assistant they already use. |
| Planful | Financial planning | Added MCP Server for external AI tools to query Planful data, with inherited dimension security. | Finance teams get AI access without losing the data boundaries they already depend on. |
| [HiBob](/companies/hibob/) | HRIS | Added MCP as live people context for AI, with references to ChatGPT, Claude, Copilot and Slack. | HR data becomes assistant context, which makes access control central. |
| Expensify | Expense management | Added an MCP server to connect live expense data with Claude, ChatGPT, Cursor and OpenClaw. | Expense data moves into the AI workbench instead of staying in a separate tab. |
| Holistics | BI / analytics | Added a semantic-layer MCP server and API connectors for Claude, ChatGPT and Cursor to query metrics externally. | Metrics become something external AI tools can ask about directly. |
| Hubstaff | Workforce analytics | Added AI-ready workforce data capabilities with REST API, CLI and MCP server for BI tools and automated reporting workflows. | Workforce data is being packaged for technical teams and agent workflows. |
| BillingPlatform | Billing / revenue | Introduced BillingPlatform AI with configuration, launch, forecasting, anomaly-detection governance and an optional MCP server for external AI models. | Billing systems are selling operational data access with governance attached. |
| Luzmo | Embedded analytics | Added Embedded MCP Server, ChatGPT/Claude/Slack/email integrations and end-to-end audit capabilities. | Embedded analytics vendors are pairing AI access with auditability. |
| Box | Content management | Introduced Box MCP server and connectors for third-party AI tools over Box content. | Content systems are exposing company knowledge to external AI tools. |

The pattern is easy to miss if you only count protocol mentions. The useful read is the data noun.

Product data. Invoice data. People context. Expense data. Metrics. Billing data. Documents.

That is what buyers care about. If an agent can reach a trusted system of record, the integration page has to explain the access clearly. If it cannot, the page is still a logo wall with a new acronym.

For SaaS teams, the practical audit is simple:

- Which business objects can an agent read?
- Are the examples tied to real work, or just setup instructions?
- Does the page name the data clearly enough for a buyer to understand the value?
- Does the access sound safe enough for IT, security or finance to tolerate?

This is the next layer of [competitor integration tracking](/blog/competitor-integration-pages/). The old audit watched partner logos, API pages and app listings. The new audit also watches the access story around the agent.

## 2. Actions added to access

The second bucket is more important than a basic data connector.

Some vendors are no longer describing agents as read-only assistants. They are describing agents that triage feedback, update roadmaps, draft changelogs, collect receivables, configure workflows, route requests or trigger work.

That changes the buying question.

Read access asks, “what can the agent see?” Write access asks, “what can the agent change?”

| Company | Category | What changed | Read |
| --- | --- | --- | --- |
| [UserJot](/companies/userjot/) | Product feedback | Added an MCP server enabling Claude, Cursor and other AI agents to triage feedback, update roadmaps and draft changelogs. | Product-feedback systems are selling action alongside reporting. |
| Ashby | Recruiting | Added an MCP Server enabling external AI tools like Claude and ChatGPT to query and act on recruiting data. | Recruiting systems are moving from search surfaces to agent-usable systems of record. |
| Chargebee | Billing | Added AI-native capabilities: MCP server, three built-in agents, OAuth, natural-language CPQ selling rules, autonomous Receivables collection agents and Credit Wallet billing. | Billing data, pricing rules and collections workflows are being opened to agents with commercial controls attached. |
| Slite | Knowledge base | Added Slite MCP server with 40+ read-write tools, human-in-the-loop approvals, parallelized queries and zero-trust permissions. | This is the strongest version of the shift: the agent can act, but the product explains the controls. |
| Cube | Planning / analytics | Added specialized AI agents and Cube MCP Server across Slack, Teams, PowerPoint, Google Slides and AI assistants via MCP. | Agent access is being wrapped into analyst and planning workflows instead of left as a developer side quest. |
| Cline | Developer tools | Added MCP Marketplace with AWS, SQLite, Stripe, Slack and 100+ developer tools. | Agent tooling marketplaces are becoming discovery surfaces for what agents can do. |
| Datadog | Observability | Added MCP Server, Pup CLI, Agent Directory and several Bits AI products. | Operational products are connecting agent workflows to developer and infrastructure work. |
| Airbyte | Data movement | Introduced Context Store, Agent MCP interface, Agent SDK and Automation Builder, then continued to position SDK, CLI and MCP querying in public copy. | Data vendors are preparing for agents that need governed paths to data pipelines and context. |

This is the part product and GTM teams should read carefully.

A read-only agent is usually easier to approve. A write-capable agent creates a different sales conversation. The buyer has to understand the blast radius. Can the agent update a roadmap item? Change a billing rule? Route a support request? Trigger a workflow? Touch customer records?

That turns a generic integration claim into a concrete product-management question.

If competitors are starting to show agent actions publicly, your team should know whether you are competing on:

- read-only answers;
- workflow automation;
- admin-controlled actions;
- human-approved actions;
- deeper system-of-record changes.

Those are not the same feature. They will not create the same objections.

## 3. Permissions pulled forward

The third bucket is where the buyer story gets serious.

Once agents can reach business data or take action, the sales conversation moves quickly to control. Who grants access? Does the agent inherit user permissions? Are tool calls logged? Can admins revoke access? Is there a human approval step before sensitive actions?

That is why some of the strongest changes were not launch announcements. They were permission, governance and security changes.

| Company | Category | What changed | Read |
| --- | --- | --- | --- |
| Tray.ai | Automation | Introduced an AI Governance layer for RBAC, audit trails, security and compliance across agents and MCP. | The control plane around agents becomes part of the product. |
| Recruit CRM | Recruiting CRM | Changed MCP authentication from local API keys to OAuth remote-server URLs with role-based access controls. | Authentication details moved toward an enterprise-ready access model. |
| Planful | Financial planning | Described external-AI data access with inherited dimension security. | Finance buyers get a security phrase they can bring to IT and the CFO. |
| Chargebee | Billing | Added OAuth and scoped AI agent roles alongside MCP server capability. | Billing-agent access is being paired with permission scope, which buyers will ask for. |
| Buddy Punch | Time tracking | Replaced Enterprise with Advanced, adding Manager Permissions via Groups, higher API & MCP limits, dedicated support and priority onboarding. | Permissions, MCP limits, support and rollout are being packaged together. |
| Nightfall AI | Security | Added MCP & AI Agent Security with prompt-injection defense, tool-call governance and MCP visibility. | Security vendors are treating agent access itself as a threat surface. |
| CloudBolt | Cloud operations | Added “AI-Ready Operations” with MCP support for governed AI-agent interactions with cloud infrastructure. | Infrastructure access raises the bar for governance language. |
| Duda | Website builder | Added AI Stack with AI Copilot, SEO assistant, MCP connector, AI widgets and client permission controls. | Agency/client environments need agent features without losing account control. |
| Wingspan | Contractor management | Added AI agents and AI assistants via a permissioned MCP server. | “Permissioned” matters when agents touch worker or contractor data. |
| Fluint | Sales / buyer enablement | Expanded the product suite with private LLM, managed agents, Context MCP, SOC 2, SSO/SAML and role-based permissions. | Agent access, trust proof and account control are being sold together. |
| Freshworks | Customer support / CRM | Added MCP support across several product surfaces to connect external AI agents and tools with configurable access and permission controls. | The permission story is being repeated across a suite, which suggests sales-ready governance rather than a one-off connector. |
| Drata | Compliance | Added AI Agent Governance and Drata API while changing the public product-card mix. | Governance language is moving closer to agent-specific risk. |

This bucket gives buyers the sales-call checklist.

If a vendor says MCP, ask:

- Does access use OAuth or a static key?
- Can access be scoped by role, workspace, account or data object?
- Does it inherit existing permissions?
- Can the agent write, update, delete or trigger workflows?
- Are tool calls logged?
- Are there rate limits or usage limits?
- Is there an approval step before sensitive actions?
- What happens when an employee leaves?
- Is the MCP server remote, local, hosted, beta or enterprise-only?

The protocol name does not answer those questions. The public page either answers them or it does not.

That is the point for competitive teams. Two rivals can both say they support MCP. One may have OAuth, scoped roles, inherited permissions, audit trails and admin controls. The other may have a setup doc and a local server. Same acronym. Very different sales story.

## 4. Agent access packaged and promoted

The fourth bucket shows whether agent access is becoming a commercial feature.

A docs page can be an experiment. A pricing row, nav item, homepage banner or plan limit is a stronger public signal. It means the vendor wants buyers to see agent access before implementation.

| Company | Category | What changed | Read |
| --- | --- | --- | --- |
| Barley | Compensation | Discontinued standalone Manager Agent add-on at $99 per manager per month; MCP access bundled into Pro. | Agent access moved from add-on economics into core plan packaging. |
| Product Fruits | Product adoption | MCP integration appeared in the pricing-table integrations section. | Agent access is visible where buyers compare plans. |
| Fibery | Work management | Replaced Workspace, Text and Smart Agent with monthly AI credits per paid seat, while Remote MCP expanded to all plans. | Internal AI and external agent access are being packaged separately. |
| Figma / FigJam | Design collaboration | Consolidated MCP capabilities into Extensibility as Figma MCP server with tiered rate limits and MCP connectors. | MCP moved into an extensibility model with usage boundaries. |
| [Otterly](/companies/otterly/) | AI visibility / analytics | Added Enterprise plan with SSO, custom terms, dedicated success manager and custom usage limits for API, MCP and Agent Analytics. | MCP limits sit beside enterprise buying terms. |
| [BuiltWith](/companies/builtwith/) | Web data | Added MCP API hosted option and x402 prepaid credit batch purchasing. | MCP access can become a usage and credit product. |
| Sumo Logic | Observability | Added Sumo Logic MCP Server to the Dojo AI pricing table; footnotes cap API calls, concurrent requests and query timeout. | MCP is being priced with operational limits buyers can compare. |
| beehiiv | Newsletter / media | Added tiered read/write MCP and Copilot access across plans. | The read/write distinction is becoming a visible packaging detail. |
| [Apollo.io](/companies/apollo-io/) | Sales intelligence | Added Apollo MCP to the product menu and footer. | MCP became a named product surface in a major sales-tech product. |
| Lattice | Performance management | Added Lattice MCP to the main product navigation and footer. | MCP moved into the product taxonomy buyers see. |
| HelpDocs | Knowledge base | Changed the top announcement banner to “Connect your favourite AI assistant over MCP.” | AI assistant connectivity became the page’s lead announcement. |
| [AccuRanker](/companies/accuranker/) | SEO | Added AccuRanker MCP for SEO data access within AI assistants, promoted via homepage banner and navigation. | Agent access is being used as a homepage-level acquisition hook. |
| Clay | GTM data / workflows | Changed homepage hero and navigation promotion from Audiences to Clay MCP. | MCP took over prime messaging real estate. |
| [Vacation Tracker](/companies/vacation-tracker/) | Leave management | Changed the top promotional banner from a free-plan announcement to an MCP integration launch. | Even focused SaaS tools are testing MCP as a stronger public message than free-plan promotion. |
| Mixpanel | Product analytics | Added Mixpanel MCP and AI Data Governance to the AI product navigation. | Data governance is being attached to AI access in the product taxonomy. |
| Proofpoint DLP | Security | Expanded product taxonomy and navigation to include dedicated AI Security for people, agents and MCP usage. | Security vendors are teaching buyers to treat MCP as a governed access surface. |

This is the section pricing, PMM and product teams should watch.

Once agent access appears in a plan row, someone has decided it belongs in the value conversation. Once it appears in navigation, someone has decided buyers need to find it. Once it appears in security copy, someone has heard the objection.

That gives you a better monitoring rule than “track MCP mentions.”

Track where the vendor puts the access:

- **Docs only:** likely technical experiment or early developer enablement.
- **Integration page:** buyer-facing proof is forming.
- **Pricing table:** packaging and monetization have started.
- **Navigation/footer:** the company wants buyers to notice.
- **Security/governance page:** procurement objections are being handled.
- **Homepage/banner:** the vendor is using agent access as a market message.

The same feature tells a different story depending on where it appears.

For Competitor Tracker's own version of that question, see the [AI-agent demo](/demo/agent/) and the [MCP docs](/docs/mcp/). Those pages are the product-side proof that the report says buyers will start looking for: what the agent can query, how it connects and what kind of record it can pull.

## 5. Repackaging reveals what vendors are learning

The final bucket is easy to ignore because it is less tidy than a launch.

Several companies moved, renamed, removed, consolidated or rebundled MCP-related features. That movement matters. Early categories are messy. Teams test where the capability belongs.

A feature might start as a standalone agent, move into extensibility, get bundled into Pro, leave one product area and reappear in another, or get wrapped in governance language.

| Company | Category | What changed | Read |
| --- | --- | --- | --- |
| FigJam / Figma | Design collaboration | Consolidated MCP capabilities into Extensibility as Figma MCP server with tiered rate limits and MCP connectors; removed support from Dev Mode, Make, FigJam and Motion. | MCP is being sorted into a more formal extensibility model with limits. |
| Barley | Compensation | Discontinued standalone Manager Agent add-on and bundled MCP access into Pro. | The commercial home for agent access changed. |
| Fibery | Work management | Multiple feature sections moved MCP in and out of highlighted capability lists while Remote MCP expanded to all plans. | The product is still testing how to present internal AI, external agents and extensibility. |
| Teams by Stack Overflow | Knowledge management | Replaced Ingest and Connect with Capture and Deliver; removed public site access, Auto-Answer App, direct file upload and MCP server write-back. | Write-back through MCP can be sensitive enough to remove or repackage. |
| Read | Meeting intelligence | Replaced a Digital Twin promotion with Claude Connector, ChatGPT App and MCP Server promotion. | Assistant connectors became the stronger public hook. |
| Dataddo | Data integration | Expanded Control Plane capabilities to include MCP for AI and agents, orchestration, governance, metadata, lineage and observability. | Agent access is being absorbed into a control-plane story. |
| Docebo | Learning management | Added Skills Intelligence, Enterprise Knowledge, AgentHub, Companion, MCP, Roleplay and Advanced Analytics while removing or renaming older learning products. | MCP appears as part of a wider product-suite reshuffle. |
| Airbyte | Data movement | MCP server section disappeared from one page while content reorganized around SDK and Context Store; MCP querying remained in hero language. | Messaging is still moving as the vendor searches for the clearest buyer frame. |
| Workato | Automation | Replaced MCP comparisons and department Genie previews with dual-plane Control Plane governance and Execution Plane automation sections. | The story moved from protocol comparison to operating model: govern the agents, then run the workflows. |
| Crazy Egg | Web analytics | Removed MCP, AI Data Connectors and Compliance Audit Log from Enterprise feature listings. | Removed MCP rows matter too; they show which agent-access claims did not survive packaging cleanup. |
| Finout | Cloud cost management | Removed MCP Server integration and AI Governance features. | A retreat is still a signal when a vendor backs away from agent/governance language. |

This is where competitive monitoring earns its keep.

A launch says the company added something. A repackaging says the company learned where the thing belongs. A removal says the old claim may have created confusion, risk or weak demand.

For a PMM, that is often more useful than another launch post.

## What this says about the market

“Everyone is adding MCP” is too broad. It misses the useful detail.

The better read is this: AI-agent access is becoming a new integration layer, and the market is sorting out how to sell it, control it and charge for it.

That creates different openings depending on the category.

If competitors are opening business data to agents, buyers may start asking whether your product can be queried from the AI tools they already use.

If competitors are adding write actions, buyers may start comparing the safety model before they compare the feature list.

If competitors are pulling OAuth, RBAC, audit trails and approval language forward, procurement questions are already entering the market.

If competitors are putting MCP into pricing, limits and credits, agent access is becoming packaging.

If competitors are moving or removing MCP claims, the category is still learning where the buyer understands the value.

The mistake is treating this as protocol news. It is buyer-access news.

## How to read a competitor’s agent-access change

Read the page like a buyer first. Then read it like a competitor.

| Signal | Possible read | Team move |
| --- | --- | --- |
| MCP added only to docs | Developer enablement or early experiment. | Check whether there is real workflow proof before reacting. |
| Business data named | Vendor is making the value concrete. | Compare which data objects your own pages make visible. |
| Agent can write or trigger work | The product is moving beyond read-only answers. | Review permissions, approvals and audit before matching the claim. |
| OAuth / RBAC / inherited permissions added | Enterprise objections are likely showing up. | Give sales and security a clear access-control answer. |
| MCP appears in pricing | Agent access is becoming packaging. | Check plan placement, credits, API limits and upgrade logic. |
| MCP moves into navigation | The vendor wants buyers to find it. | Decide whether agent access belongs on your integration, product or developer pages. |
| MCP removed or rebundled | The first packaging may have been wrong. | Watch for a replacement story: governance, extensibility, credits, API or control plane. |

This is the practical use of the report. It gives a SaaS team a way to sort the noise.

Do not ask, “does our competitor mention MCP?”

Ask what the mention is doing:

- proving access;
- showing a workflow;
- handling risk;
- creating an upgrade;
- changing the product story;
- retreating from a claim that did not land.

Those reads lead to different moves.

## What to watch next

If this pattern continues, the next changes will likely show up in specific places:

- integration pages explaining exactly what data agents can reach;
- setup docs moving from local servers to hosted/OAuth paths;
- plan tables adding MCP, API, agent, credit or rate-limit rows;
- security pages adding tool-call logs, prompt-injection controls and approval flows;
- product pages showing agents that can update, route, draft, triage or trigger work;
- homepage banners testing whether agent access is a stronger message than a feature launch;
- old agent add-ons being folded into core plans;
- MCP claims being removed where the packaging or risk story was weak.

The exact wording matters. “AI-ready” says very little by itself. “Claude can query invoice-to-cash data with inherited permissions” says much more.

That is what buyers and competitors should watch.

## The read

The integration page is getting a new job.

It still has to show which tools connect. Now it also has to answer what an AI agent can safely access.

Some companies are opening business data. Some are letting agents act. Some are pulling permissions and audit language forward. Some are putting agent access into pricing. Some are moving or removing the claim as they learn where buyers understand it.

That is the signal worth tracking.

The market is not waiting for everyone to agree on the perfect category name. It is already leaving traces in navigation, docs, pricing tables, banners, security pages and plan limits.

Competitor Tracker watches the websites your competitors keep changing: pricing pages, plan tables, feature lists, comparison pages, integration pages and positioning copy. One coin tracks one competitor for one month; the first 25 are on the house.

See a [sample dossier](/demo/), try the [agent view](/demo/agent/) or [start a case](/#engage).

*— C. T. Lucky*


---

Source: https://competitortracker.io/blog/what-can-the-agent-access/
Updated: 2026-08-23
