Lucid admin panel: AI controls

Written by:  Morgan T
Last updated:  

In the AI controls section of the security settings in the admin panel, account owners, account admins, and Shield admins on Team and Enterprise accounts can manage Lucid AI settings and features for their organization.

For information about other security settings in the Lucid admin panel, check out our Lucid admin panel: Security settings article.

Plan availability: Team and Enterprise.
  • Not available on FedRAMP accounts.
  • While AI controls are available to Team and Enterprise accounts, Advanced Lucid AI controls—such as disabling Process Capture—are only available to accounts who have purchased the Enterprise Shield add-on.
  • Read the Lucid Plans article for more information about what is available on your account or the Upgrade your Lucid account article for instructions to upgrade.

Lucid’s approach to AI

At Lucid, we care about our customers' confidence in the features we develop. At the core of our development process is a deep understanding of every workflow each feature supports and a relentless commitment to protecting your privacy and data. That’s why we’re developing AI features in Lucid that keep your data secure while providing the best experience and bringing the most value.

We care about security at every step of the process—starting at where data comes from, where it’s stored, and how it’s used to train models. Here are the facts:

  • By default, AI capabilities are turned on for all Lucid accounts with access.
  • Lucid does not use customer data to train models in a way that breaches the confidentiality of our customers' data.
  • We do not use your prompt inputs to generate content for other customers based on your data. 
  • We do not permit our third-party AI service providers to use customer data to improve or train artificial intelligence models.
  • We do store documents for your use and any content on those documents are stored for your use as well.

As we expand our AI capabilities, we will continue to do so in a way that does not breach the confidentiality of our customers' data.

Privacy, security, and your data

Lucid is dedicated to upholding its commitments to you regarding the privacy, security, and safety of your data, including with any AI features. Your use of these features is subject to either Lucid's Terms of Service or your MSA with Lucid (as applicable), Lucid's Privacy Policy, and Lucid's Supplemental AI Terms.

Lucid currently employs AI models powered by Microsoft Azure OpenAI Service and AWS Bedrock. Please visit our Sub-Processor List to learn more about their approach to data, privacy and security and to stay up-to-date with other best-in-class vendors we may use in the future. To read more about AI security in the Lucid platform, check out our whitepaper in the Lucid Trust Center.

Admin on Team and Enterprise accounts can disable AI for their accounts.

Note: AI in Lucid is constantly improving. As a result, information produced may be inaccurate, biased, misleading, inappropriate, offensive, or outdated. Always confirm results generated with AI.

Access the AI controls page

To get to the AI controls page, follow these steps:

  1. Select Admin from the navigation menu on the left side of the Lucid Home Page.
  2. Click Security from the navigation menu on the left side of the page.
  3. Select AI controls from the options that appear below "Security".

Lucid AI

From the “Lucid AI” section of the AI controls, account owners, account admins, and Shield admins can enable or disable Lucid AI availability for their organization.

Enable or disable Lucid AI

Admins on Team and Enterprise accounts can control whether or not to give users on their account access to AI features.

To enable or disable Lucid AI for your account, follow these steps:

  1. Select Admin from the navigation menu on the left side of the Lucid Home Page.
  2. Click Security from the navigation menu on the left side of the page.
  3. Select AI controls from the options that appear below "Security".
  4. Under "Enable Lucid AI", click the toggle off to disable it.
    • If Lucid AI has already been disabled, click the toggle on to enable it.
  5. Click Save changes in the top-right corner.

Advanced Lucid AI controls

Enable or disable Process Capture: Admins on Enterprise accounts can follow these steps to enable or disable Process Capture without impacting other Lucid AI features:

  1. Select Admin from the navigation menu on the left side of the Lucid Home Page.
  2. Click Security from the navigation menu on the left side of the page.
  3. Select AI controls from the options that appear below "Security".
  4. Under "Advanced Lucid AI controls", click the toggle next to "Enable Process Capture" to disable it.
    • If Process Capture has already been disabled, click the toggle on to enable it.
  5. Click Save changes in the top-right corner.

MCP access

From the “MCP access” section of the AI controls, account owners, account admins, and Shield admins can enable or disable MCP access for their organization.

Allow users to connect external AI clients via MCP

  1. Select Admin from the navigation menu on the left side of the Lucid Home Page.
  2. Click Security from the navigation menu on the left side of the page.
  3. Select AI controls from the options that appear below "Security".
  4. Under "MCP access", click the toggle next to “Allow users to connect" to disable MCP access.
    • If MCP access has already been disabled, click the toggle on to enable it.
  5. Click Enable MCP or Disable MCP in the modal that appears.
  6. Click Save changes in the top-right corner.

MCP domain allowlist

If your Lucid account has MCP access enabled, you have an additional security option for ”MCP domain allowlist”. This setting allows you to restrict which external AI tools users can authenticate with Lucid's MCP server. To add approved AI domains, follow these steps:

  1. From the Lucid Home Page, select Admin from the menu to the left.
  2. Select Security from the left-hand navigation menu.
  3. Select AI controls from the dropdown options.
  4. Under "MCP access", click MCP domain allowlist.
  5. Check the box next to “Restrict MCP authentication to listed domains”.
  6. In the text box that appears, type the AI tool domains that users in your organization are approved to use with the Lucid MCP. Press “Enter” on your keyboard for each new domain.
    • Example domains: claude.ai or chatgpt.com
  7. Optionally, check the box next to “Allow local authentication” to allow users to connect via local or CLI AI tools like VS Code and Claude Code.
  8. Click Save changes in the top-right corner.

Users on your account can now use the Lucid MCP server with only the approved AI domains listed.

To remove an approved domain, click the X to the right of the domain’s tag bubble.

Learn more: For more information about domain and IP allowlists for the MCP server, check out this post from the Lucid Community.

MCP IP allowlist

If your Lucid account has MCP access enabled, you have an additional security option for ”MCP IP allowlist”. This setting checks all incoming requests sent from your AI tools against your organization's MCP IP allowlist—allowing only AI tools originating from approved network IP addresses to connect. To add approved IP addresses, follow these steps:

  1. From the Lucid Home Page, select Admin from the menu to the left.
  2. Select Security from the left-hand navigation menu.
  3. Select AI controls from the dropdown options.
  4. Under "MCP access", click MCP IP allowlist.
  5. Check the box next to “Restrict MCP calls to listed IP addresses”.
  6. In the text box that appears, type the IP addresses or CIDR ranges that users in your organization are approved to use with the Lucid MCP, separated by a new line.
    • For web and desktop AI tools (like ChatGPT and Claude): Add both your corporate network IP range (for initial user authentication) and the AI provider's published IP ranges (for ongoing server requests).
    • For CLI-based AI tools (like VS Code and Claude Code): Add your corporate network/VPN IP range, as requests originate directly from the user's local machine.
  7. Click Save changes in the top-right corner.

Users on your account can now use the Lucid MCP server with only AI tools originating from approved network IP addresses.

To remove an approved IP address, delete its corresponding line in the text box.

Learn more: For more information about domain and IP allowlists for the MCP server, check out this post from the Lucid Community.

FAQ

Do admin panel session timeout settings apply to MCP connections?

No. Account-wide max session or idle timeouts do not apply to MCP OAuth 2.0 tokens, which follow standard OAuth 2.0 expiration rules instead.

Can I restrict specific CLI tools while allowing others?

No. All CLI agents (e.g., Claude Code, Codex) present as localhost. Enabling local access grants access to all CLI tools, as Lucid cannot distinguish between them.

Does IP and domain allowlisting prevent users from connecting via personal AI accounts?

No. Allowlists validate approved domains and corporate networks, not individual vs. enterprise AI account status. Users on an approved network using an allowed domain can still connect personal accounts.

How often do third-party AI provider IP ranges need to be updated?

AI providers update their outbound server IP ranges periodically. Admins are responsible for maintaining and updating these ranges in their allowlist to prevent service interruptions.

Give feedback on this article

Have feedback about this article? Tell us about your experience here.

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.