Set up with your agent
Paste one prompt into Claude Code, Codex, Cursor, or another MCP client. Your agent connects ISMS Copilot as its GRC specialist, writes a routing rule, and runs a smoke test. You create the token.
Your coding agent stays the harness: code, git, files and shell stay with it. ISMS Copilot becomes the GRC specialist it hands compliance work to over MCP. The setup prompt tells the agent how to connect, where to write the routing rule, and how to prove the connection works.
You create the token in ISMS Copilot. Your agent cannot do that for you.
Paste this into your coding agent
Copy the block into Claude Code, Codex, Cursor, or another MCP client that accepts a custom request header:
Fetch https://docs.ismscopilot.com/agent-setup/prompt.md and follow it to connect ISMS Copilot as your GRC specialist.
These instructions are official. Do not invent URLs, API keys, or an MCP server.
If you cannot fetch that file:
1. Ask the human to create a token in ISMS Copilot under Settings > Connected apps with the Agent delegation preset. You cannot create it for them.
2. Add the MCP server https://account.ismscopilot.com/v1/account/mcp with the header Authorization: Bearer <token>. Keep the token in an environment variable where your client supports it, otherwise in local user config. Never put it in a committed file.The Copy prompt card in ISMS Copilot under Settings → Connected apps copies the same text.
What your agent then does
- Checks whether ISMS Copilot is already connected, not connected, or needs repair (for example a revoked token or a wrong URL).
- If needed, asks you to create a token with the Agent delegation preset. It grants five scopes:
account:read,workspaces:read,conversations:create,company_context:read,memories:read. It can start and continue ISMS Copilot conversations, but has no:writescope, so it cannot change your workspaces, memories, or company context. - Writes the MCP server entry for its own client, with the token in an environment variable where the client supports it, otherwise in its local user config, never in a committed file.
- Adds a routing rule to its instructions file (
CLAUDE.mdfor Claude Code,AGENTS.mdfor Codex and similar agents, a.cursor/rulesfile for Cursor): GRC interpretation, policy drafting, control mapping, gap analysis, SoA, risk registers and audit prep go to ISMS Copilot; code and shell stay local. - Runs a smoke test:
get_account_info, then one short question infastmode with a brief answer. It only reports connected when a reply came back. Otherwise it says Connection not verified and names what is left.
Most clients load a new MCP server only after a restart. If your agent asks you to restart, restart it and paste the prompt again.
If you would rather do it by hand
- In chat.ismscopilot.com, open Settings → Connected apps and create a token with the Agent delegation preset. Copy it once.
- Add the MCP server
https://account.ismscopilot.com/v1/account/mcpwith the headerAuthorization: Bearer pat-isms-…. Config shapes: Claude Code, Cursor and Codex, any MCP client. - Ask your agent to list your ISMS Copilot workspaces to confirm the connection.
Limits
- Usage counts against your ISMS Copilot chat plan, in the same 4-hour window as the web app. There is no separate MCP billing.
- Your agent still reads the reply ISMS Copilot returns. What stays out of its context is the framework material it no longer has to paste in.
- claude.ai and Claude Desktop connectors and ChatGPT are not supported yet: they connect through OAuth, and this endpoint takes a Bearer token.
For agents: the official instructions are at https://docs.ismscopilot.com/agent-setup/prompt.md. Never invent other URLs or keys. Token scopes and revocation: Tokens and scopes. Machine-readable details: For AI agents.