Workspace clients
On Enterprise, open Clients and use the Workspace clients tab to see installs across people. You can search, drill into a person, spot stale clients, and revoke a device so that connection must sign in again. Members can always revoke their own devices from their personal AI Clients view. Workspace-wide listing and admin revoke require Enterprise.Require registered clients
Under workspace Settings → AI client access, Enterprise admins can:- Allow dynamic clients — whether unrecognized client identifiers may connect.
- Require registered AI clients — only clients Passport recognizes (or you have registered) may attach.
requireRegisteredClients off, dynamic clients allowed) even if older Enterprise values remain stored.
Team client defaults
Client defaults decide which granted MCPs appear by default in a given AI client for a team. They do not grant new access; passes still decide what a person can reach. See Client defaults.Related
- Member quickstart for connecting a client
- People and teams for roles and lifecycle
- Network and egress for how the desktop app and bridge talk to Passport