Anthropic is pushing Claude toward a more integrated way of working. With a new extension to the Model Context Protocol (MCP), Claude can open tools like Slack, Asana, Figma and Canva as interactive experiences inside the chat window. Instead of getting a text response and switching tabs, users can preview, refine and adjust work in place.
It’s a solid usability upgrade. It also reflects a broader shift in how AI is being productised: chat is becoming the command surface, and applications are becoming embedded workspaces.
But for enterprise IT and collaboration leaders, this announcement is only part of the story. The industry is already past the question of whether an assistant can connect to tools. The harder question is whether enterprise AI agents can be trusted to act. That means identity, permissions, governance and accountability.
MCP Apps improve the user experience, not the risk model
The in-chat app experience addresses a common weakness of earlier AI integrations. When assistants only return text, users have to copy and paste into the target application, then fix formatting, validate outputs, and deal with the gap between what the assistant suggested and what the app can actually accept.
Embedded, interactive apps reduce that friction. They also encourage review. A user can see a Slack message before it posts, or adjust a Canva deck before it’s exported and shared. In practical terms, that can cut rework and reduce simple mistakes.
This is why “apps inside chat” is gaining momentum across the market. People do not want a separate assistant sitting off to the side. They want work to move faster in the systems they already use.
Enterprise AI agents are now an identity and permissions challenge
Tool access is quickly becoming table stakes. The enterprise challenge is delegated authority.
Drafting a Slack message is low stakes. Posting into the wrong channel is not. Creating new spaces, inviting external guests, pulling customer data into a conversation, or triggering actions across connected systems can all carry compliance and security implications.
As soon as an AI agent can do more than draft, enterprises start asking different questions. Which identity is the agent using when it takes an action? Is it acting as the employee, as a bot identity, or as a service account? What permissions does it inherit, and can those permissions be scoped to a task and time-limited? Can admins restrict the agent to “draft only” modes, or require explicit approval before publishing?
MCP may standardise how tools and data are reached but it doesn't automatically solve identity and governance. For enterprises, those controls are the foundation of safe deployment.




