AI Agents (MCP)
Write and sync access: what your assistant can change
What your AI assistant is allowed to touch, how the write and sync access switch changes that, and how to disconnect a tool you no longer use.
Handing an AI assistant the keys to your help center is a fair thing to be careful about. This article explains exactly what it can and cannot do, what the write and sync access switch changes, and how to take access away again.
Two separate gates
Your assistant has to get through both of these before anything about your live site can change.
Notion access decides whether it can write at all. Without your Notion pages shared with HelpKit, every draft and every edit is refused.
Write and sync access decides whether it can touch what your visitors already see. This one is a switch in your dashboard, per project, and it is the setting worth understanding.
With write and sync access off
This is the safe default, and plenty of teams stay here happily.
Your assistant can read everything: your structure, your articles, your analytics, your feedback and your search insights. It can also write new drafts into Notion.
What it cannot do is anything a reader would notice. Publishing an article, editing one that is already live, archiving something, renaming a category and running a sync are all refused. Drafts stay invisible until you tick Published in Notion yourself.
In practice you get a well briefed writer who leaves work on your desk, and you decide what ships.
With write and sync access on
Your assistant can additionally publish articles, edit live ones, archive articles and categories, rename categories, and sync your help center, so its work can actually reach your visitors.
Two things stay true even then. New articles are still created unpublished, every time. And your assistant only publishes or removes something when you ask it to in that conversation. It will not decide on its own that an article deserves to go live, however good the analytics look.
Turning it on
Open Account Settings → MCP and switch on MCP has write and sync access.
The switch is per project, not per person, so it applies to every assistant connected to that help center. Only the project owner can change it.

Nothing is live until a sync runs
This catches people out, so it is worth stating plainly. Publishing an article and putting it on your site are two different steps. Ticking Published marks it as ready. A sync is what actually rebuilds your live help center.
Your assistant knows this and will normally offer to sync after publishing. If it says something is published, it is fair to ask "is it actually live yet?"
Who can connect
MCP needs the Editor role on a project. If you have the Viewer role, your assistant will not be able to reach that help center, and your dashboard says so. A project admin can change your role under Settings → Members.
Where your data goes
When you ask a question, the relevant part of your help center is sent to whichever AI tool you are using, which means its provider handles it: Anthropic for Claude, OpenAI for ChatGPT, and so on. It is the same as pasting that information into a chat window yourself.
Your AI tool never receives your HelpKit password or your Notion password. Connections are approved in your browser, and the approval can be withdrawn at any time.
Your assistant also inherits your own permissions exactly. It cannot reach a project you cannot reach, change your billing, cancel a subscription, or create new connections of its own.
Managing and removing connections
Every tool you approve appears in Account Settings → MCP, under Connected clients & keys. Each one is separate: revoke a single connection and the others carry on working. A revoked connection stops working within a few minutes.
The same list holds keys, which start with hk_. You only need a key for tools that cannot open a browser to sign in, such as Codex, scripts and automated systems. Keys stay valid until you delete them, so delete any you are no longer using.