Lattice is a people management platform for performance reviews, goals, feedback, one-on-one meetings, and employee growth.
Agen.co connects to Lattice through Lattice's own hosted MCP server as an Official connector. A Lattice admin creates the MCP server in Lattice, and each user then signs in with their own Lattice account, so agents only reach the data that account is allowed to see.
Prerequisites
Prerequisites
- A Lattice admin to create the MCP server in Lattice. Creating it needs Lattice admin access.
- A Lattice account for each person whose agents will use the connector.
Lattice does not support dynamic client registration, so an admin creates the MCP server in Lattice and gives Agen.co its Client ID and Client Secret. Lattice needs Agen.co's callback URLs for that, so start in Agen.co.
- In the Agen.co portal, go to Connectors → My connectors and click Add connector.
- In the Select connector drawer, search for
Latticeand select it. The Add Lattice panel opens. - Copy both read-only URLs at the bottom of the panel:
- Callback URL — completes the initial OAuth handshake between Agen.co and Lattice.
- Gateway callback URL — used by the Agen.co MCP gateway for per-user authorization at runtime.
Leave this panel open — you return to it after creating the MCP server in Lattice.
- In Lattice, go to Admin → Platform → MCP Server and click Add MCP Server.
- Paste both callback URLs from Agen.co as redirect URLs, adding each one individually.
- Copy the Client ID and the Client Secret.
Return to the open Add Lattice panel and fill in the fields:
| Field | Required | Description |
|---|---|---|
| Instance Slug | Yes | Namespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with lattice. Use lowercase kebab-case. You can change it later from the connector's settings. |
| Client ID | Yes | The OAuth client ID from your Lattice app. |
| Client Secret | Yes | The OAuth client secret from your Lattice app. |
| Callback URL | — | Read-only. Add it as a redirect URL in Lattice. |
| Gateway callback URL | — | Read-only. Also add it as a redirect URL — the MCP gateway uses it for per-user authorization at runtime. |
- Click Connect. You are redirected to Lattice to sign in and approve access. Lattice asks for your company's Lattice subdomain during sign-in.
- After you approve, the panel switches to Select the tools to import from Lattice. Every tool is on by default; turn off any you do not want your agents to see.
- Click Add. The connector is created and the selected tools are imported only when you click Add — if you close the panel first, nothing is saved, even if the Lattice callback page reported success.
The Lattice MCP server publishes these scopes, which show what it can reach:
| Scope | Area |
|---|---|
mcp:employees.read | Read employee information |
mcp:goals.read | Read goals |
mcp:grow.read | Read growth data |
mcp:feedback.read, mcp:feedback.write | Read and write feedback |
mcp:meetings.read, mcp:meetings.write | Read and write one-on-one meetings |
mcp:reviews.read, mcp:reviews.write | Read and write reviews |
mcp:updates.read, mcp:updates.write | Read and write updates |
Agents can read goals, growth, and employee information, but the scopes list no write access for them. The scope list was read from the server on 2026-10-05 and can change.
Enabling the Lattice connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.