Sonata

Documentation · For administrators

Connections

Sonata connects only to systems it has vetted: official first-party servers from a pre-vetted catalog, or a server your own organization hosts. There is deliberately no way to connect an arbitrary third party.

Allowed connections and the capability ceiling

Before any specific server, a standing guardrail decides what the organization permits at all: which connection categories are allowed, from file storage and mail through MCP servers, and the capability ceiling, whether agents may act read-only or read-and-write. The ceiling is the most any connection can do, regardless of what an individual connection could otherwise offer. Tightening the policy takes effect immediately, including for connections granted earlier, so it is a real revocation, not just a setting for new connections.

The catalog

The catalog covers the systems legal teams live in: contract lifecycle, document management, e-discovery, court data and research, and the productivity layer around them. Each entry says honestly what it needs, like requiring your own Ironclad account. Verified means Sonata has proven the full path live, connect, discover tools, and run a real read; available means pre-vetted from a trusted source and verified as customers enable it. Google Workspace is verified end to end today.

Connecting a system

Connecting is a super admin action: pick the server, sign in with the organization’s own account for that system, and approve the access it asks for. At connection, Sonata discovers what the server can do and shows you the tool list. Two policies must both agree before a connected system is available to an agent: the server is connected and healthy, and the MCP category is allowed in Policy and access.

Credential custody, in plain language

The keys and tokens a connection produces are encrypted and stored in a vault only the server can read. They never reach a browser, never appear in logs, and are deleted when you disconnect. When a token expires, Sonata renews it itself. What you see in the interface is only the connection’s status, never its secrets.

Content libraries

Alongside connected systems, you decide which curated content libraries, like Claude for Legal, the organization shows. Turning a library off genuinely hides its agents everywhere in the organization, not just from a list; a quiet line shows when each library was last updated from its source.

How to

Set the capability ceiling and allowed categories

Super admin only; org admins see the policy read-only.

  1. Under Allowed connections, set the most any connection can do: Read only, or Read and write.
  2. Toggle the categories your organization permits, from file storage and mail through MCP servers.
  3. Tightening takes effect immediately, including for connections granted earlier.

Connect a system from the catalog

Super admin only; org admins see connection state read-only.

  1. Open Policy & access and find MCP connections.
  2. Expand the provider group and select Connect on the server.
  3. Sign in with the organization’s own account for that system and approve the access it asks for.
  4. Sonata discovers the server’s tools and shows Connected with the tool count; Show tools lists exactly what agents can reach.

Connect your own server

  1. Under Your own server, enter the MCP server URL. It must be https, and it authenticates with OAuth 2.1.
  2. Select Connect and complete the sign-in your server presents.

Disconnect or reconnect

  1. Select Disconnect on a connected server; the connection and its stored credentials are removed.
  2. A server showing Needs reconnect has lost its grant; select Reconnect and sign in again.

Turn a content library on or off

  1. Under Content, toggle the library, like Claude for Legal.
  2. Off hides that library’s agents everywhere in the organization until you turn it back on.

All documentation · Everything above describes the product as it ships today. If something here doesn’t match what you see, tell us.

← Back to documentation