Supported tools
Learn what you can do with HighQ MCP Server tools
The HighQ MCP Server provides AI tools a read-only window into HighQ content. AI assistants can use these tools to find, read, and analyse the files, iSheets, and matter data a user already has access to. Administrators can audit and govern activity across the wider instance.
The surface is strictly
read-only
. Tools find information and answer questions; they never
create, modify, or delete anything. Every response is permission-bounded, so a tool only ever returns content that the requesting user is already allowed to see in HighQ.However, the real power comes from combining tools. In a single prompt, an AI assistant can search a workspace, open the documents it finds, pull the relevant text, and check who last changed a related record, chaining several tools to answer one question.
How are the tools organised?
The HighQ MCP Server provides two groups of tools:
- Core content tools- Work across the HighQ sites and content a user has access to, with every result permission-bounded. These tools form the everyday experience for matter members and external clients.
- Audit tools- Span the wider HighQ instance and are available to system administrators for oversight and governance.
Core tools
The MCP Server exposes
16 read-only
tools that cover files, iSheets, and matters. These tools enable users to browse folder structures, read and summarise documents, list and filter iSheet records, view record-level change history, look up people and permissions, and search content.These tools are
not limited
to a single site. Users can work across all HighQ sites they have access to, querying a specific site or searching across multiple sites, and every result is permission-bounded, returning only content the user is already allowed to access.The following table lists the 16 available API tools, organised into 9 categories, and describes the purpose of each category along with the tools it contains.
Category | What it does | Tools |
|---|---|---|
Site discovery & overview | Finds sites, and read one site's configuration and categories. |
|
Folder navigation | Browse's a site's folder tree, or read one folder's metadata and path. | list_folders |
File listing & metadata | Lists the files in a folder, and read one file's stored record. |
|
Document reading & summarisation | Pulls document's extracted text, in pages. | get_file_text |
Content search | Searches documents, folders and people, instance-wide or scoped to a site. | search_content |
Matter data & registers (iSheets) | Discover a site's iSheets, their columns and saved views. |
|
iSheet record data | Searchs or lists the rows of one iSheet, with column filters. | search_isheet_items |
People & access lookups | Lists a site's members, or search accounts across the instance. |
|
Favourites | Lists the caller's own bookmarked items. | list_favourites |
note
The naming and terminology of the tools may change; however, their functionality will remain consistent.
What the core tools can't do?
Core tools are read-only: they observe and report, but do not make changes. Any updates to HighQ content must be performed directly in HighQ.
Currently, the tools cannot:
- Create content- No creation of sites, folders, iSheets, or iSheet records/items.
- Write to iSheets- No editing, updating, or appending of records, columns, or values.
- Upload or modify documents- No uploading new files or versions, and no editing of document content.
- Delete content- No removal of files, folders, records, or sites.
- Move, copy, or rename content- No changes to files, folders, or records.
- Manage people or permissions- No adding or removing users, or changing roles and access.
- Change configuration- No updates to admin settings, site setup, or workflows.
- Share or notify- No issuing of shares, invitations, or notifications.
If a prompt requests any of these actions, the tools do not perform the operation. The required changes must be completed directly in HighQ.
Audit tools (instance / system level)
On top of the read-only site surface, the MCP Server provides four audit tools for administrators who require oversight across the wider HighQ instance. These tools cover sign-in and access activity, site lifecycle events, membership activity, and content activity.
Audit queries perform best when they are kept narrow and bounded, focused on a single activity type, a short time window, and, where relevant, a single site.
Category | What it covers | Tool |
|---|---|---|
Instance-wide audit (system administrators only) | Sign-ins, membership and role changes, site lifecycle, and content activity, one domain per query. | list_system_audit_events |
iSheet record change history | Who changed which row of one iSheet, and when. Needs site Reporting-admin rights. | list_isheet_audit_events |
note
Audit tools operate at the instance level and aggregate audit data from all sites within your HighQ instance. Site-level audit API exposure is not supported. Audit tools respect instance boundaries, so audit data from other instances cannot be accessed.
What the audit tools can't do?
Like the core tools, audit tools are read-only reporting tools. They surface activity that has already occurred and do not act on it.
The tools cannot:
- Take any remediation action- No suspending or removing users, revoking access, ending sessions, or changing settings in response to audit findings.
- Modify or clear the audit trail- Audit records cannot be edited or deleted through the tools.
- Be used by non-administrators- Access is limited to system administrators; standard users and site administrators cannot query audit data through the MCP Server.
- Return site-scoped audit data- Audit data is aggregated at the instance level; site-level audit API exposure is not supported.
- Cross instance boundaries- Audit data from other HighQ instances cannot be accessed.
How do tools work together?
Most useful answers come from chaining tools. For example:
- Find, then read- Search for a document by title, then extract its text and summarise it.
- Navigate, then list- Open a site's folder structure, then list the files in a specific folder.
- Query, then explain- Find open items in an iSheet, then review the change history of a specific record.
- Govern- Review instance-wide sign-in activity, then investigate related workspaces or membership changes.
Using the tools across AI Assistants
The same HighQ MCP Server works across MCP-compatible AI assistants, including Claude, ChatGPT, Gemini, and Microsoft Copilot, as well as custom in-house AI tools.
The underlying capabilities are consistent across assistants; only the way tool names are displayed may vary slightly between them. Regardless of the assistant you're using, the surface remains read-only and permission-bounded, and users can only view content they are already authorised to access in HighQ.
Permissions and access
- Core site-level tools return only the content that the requesting user is permitted to see in HighQ.
- Audit tools are restricted to system administrators.
- Standard users and site administrators cannot query instance-level audit data through the MCP Server.
- Non-administrators receive aninsufficient permissionserror when attempting to query audit data.