New features are continuously being added to iManage MCP Server. Refer to the enhancements and feature changes available in each update.
September 2026
Deny option for clients pending approval
Administrators can now deny a client's connection request directly from the Pending Approval section in iManage Control Center, instead of adding the client and then removing it from the Allowed MCP clients section. Selecting the icon next to a client removes it from the list. If the client tries to connect again, it reappears in Pending Approval for review.
For more information, refer to Reviewing pending approvals for MCP clients.
Removal of the five-client limit in the Pending Approval section
The Pending Approval section in iManage Control Center is no longer limited to showing five clients at a time. Administrators can scroll through the full list of clients awaiting approval, regardless of how many are pending.
For more information, refer to Reviewing pending approvals for MCP clients.
Reduced default refresh token expiration for iManage MCP Service
The default refresh token expiration for iManage MCP Service is now 7 days, reduced from the previous 365-day default. This shortens how long a refresh token stays valid before requiring re-authentication, improving the security posture of the application.
The new default is applied automatically when you add this application in iManage Control Center. As an administrator, you can still customize this value; the change affects only the default.
For more information, refer to Adding the iManage MCP application in iManage Control Center.
July 2026
Manage client and user access and configure tool permissions for iManage MCP Server in iManage Control Center
iManage MCP Server now offers administrators significantly more control through expanded configuration options in iManage Control Center. The new MCP Settings page lets administrators customize how MCP-enabled clients connect to and interact with iManage data.
With the new settings, administrators can:
Control which clients can connect: Specify exactly which MCP-enabled clients are permitted to access iManage MCP services, either by selecting from a list of available clients or adding a custom client URL. Clients that attempt unauthorized connections are automatically flagged for review.
For more information, refer to MCP Clients.
Define granular access policies: Create and manage access policies that determine which iManage MCP tools are available to clients across iManage Work, iManage Tracker, iManage Search, and iManage Insight—with the flexibility to apply permissions broadly or fine-tune them per client.
For more information, refer to Access Policies.
Manage user and group access: Decide who in your organization can use iManage MCP Server and apply the right access policy to the required users or groups.
For more information, refer to Assign Access Policy.
