AI & MCP
The assistant
The assistant inside Elevate Team: what it can do, what it always asks before doing, and how it differs from a key connected over MCP.
The assistant lives inside the app, on the web and on the phone. It runs as you: your role, your permissions, your account. It cannot see a client you cannot see or move a crew you cannot move.
What it is for
Three kinds of question, roughly:
Find. "What did we do at 14 Alder Street last spring?" "Which quotes are older than a week with no reply?" "Is Crew B free Thursday afternoon?"
Decide. "Who should take this callback?" "Which of Thursday's roofing visits should move?" "Is this job making money?"
Do. "Draft a quote for the compressor replacement from the usual items." "Move the Ridgeway visit to Friday and tell the customer." "Log the two capacitors used on the Northline job."
Confirmation is the boundary
Anything that reaches a customer or moves money is confirmable: the assistant prepares it and shows you exactly what will happen, and nothing leaves until you press the button.
Sending a quote, issuing an invoice, taking a payment, texting an arrival window, cancelling a visit. All confirmable, all of them, every time. The assistant can compose the message and stage the send; a person completes it.
Everything else happens directly: searching, drafting, scheduling internal work, recording stock already used. Each of those is reversible from the board and reaches nobody outside the business.
Assistant versus an MCP key
They share the same tool implementations, and then diverge on purpose.
| | Assistant (in app) | MCP key | | --- | --- | --- | | Acts as | The signed-in person | The membership that issued the key | | Confirmable actions | Yes, with a person present to confirm | Not reachable at all | | Business configuration | Can change crews, checklists, templates | Cannot | | Access notes, leave reasons | Visible if your role allows | Withheld | | Audit entry | Names the person | Names the key and its holder |
The short version: the in-app assistant has a human in the room, so it is allowed to prepare things a human then approves. A key has nobody in the room, so anything requiring approval is simply absent. See the MCP page for the full list.
Prompt injection, honestly
The assistant reads customer messages. Customer messages are written by people who are not you, and occasionally by people who would like your assistant to do something on their behalf.
The defence is not clever prompting. It is that the actions that matter are not available without a person pressing a button, and the tools that would leak sensitive material are not in the catalogue at all. An instruction hidden in an inbound email can, at worst, get the assistant to draft something silly that a person then declines to send.
Getting good answers
- Name things the way your business names them. The assistant reads your price book, job types and checklists; it does not know the nickname for the Ridgeway job unless the Ridgeway job is called that.
- Ask for the decision, not the screen. "Who should take this?" produces a better answer than "show me the schedule", because the first question lets it use several tools.
- Correct it once. Corrections apply to the conversation, and the account's vocabulary settings carry across conversations.
Turning it off
Per account, in Settings → Assistant. Turning it off removes the assistant from every surface and revokes nothing else; API keys and MCP access are managed separately in Settings → Developers.