Why a capability is missing, or a request failed
Almost every MCP problem is one of three things: your role, your key, or which account the key belongs to.
Your assistant is only ever handed the capabilities you're authorized for — anything else never reaches it. So when you're not authorized, your assistant says it can't do something rather than saying you're not allowed. "Missing" and "not permitted" look identical from where you're sitting.
"My assistant says it can't do that"
That capability isn't available to your key. Check these three, in this order:
- Your role. Members and Auditors can read your compliance data but not change it — changing anything needs Owner or Administrator. If your colleague's assistant can do something yours can't, this is almost always why: nothing is broken and there's nothing to reconfigure. Ask an Owner or Administrator in your organization to change your role.
- Your organization's modules. A capability only exists for you if your organization has that part of UprootSecurity enabled.
- The wrong account's key. If the key in your configuration belongs to a different person or a different organization than you assume, your assistant is working as them, not you. Ask it: "Who am I connected as in UprootSecurity?" — it will read your name, organization and role back.
What your assistant can see — and what it can change has the full model.
"It can't connect at all, and everything is rejected"
The key is wrong, or it isn't being sent correctly. Almost always one of these three:
- The key is pasted wrong or partially — every UprootSecurity key starts with
uprs_. - The word
Beareris missing in front of it. - The configuration still holds a key that has since been regenerated.
Re-paste the endpoint and key exactly as Connect your AI assistant to UprootSecurity shows, then restart your assistant so it reads the configuration again.
"It worked yesterday and not today"
The key was regenerated — by you, or by whoever's key is in that configuration. Regenerating retires the old key immediately, so every place still holding it stops working until you paste in the new one. Update all of them: each assistant, each machine, each configuration file.
"I lost my key"
Your key is shown once, when you create it, and there is no way to see it again. Regenerate to get a new one, copy it right then, and update everywhere the old one lives — regenerating retires the old key immediately.
"I uploaded evidence and the test didn't change"
Don't ask your assistant to re-run the test. Confirming the upload already re-evaluates it. Ask your assistant to read the test back instead — its status and its evidence. Give it a moment first; evaluation isn't instant. Uploading evidence with your assistant walks through the full flow.
