Welcome to Zuora Product Documentation

Explore our rich library of product information

Tenant access to AI

Understand how Zuora AI access is controlled by tenant settings, user permissions, and organizational guardrails.

Zuora AI access is controlled at the tenant, user, and role levels and follows existing Zuora role-based access controls. The tenant-level AI mode also controls which actions Zuora MCP allows when it is connected to third-party AI tools. For more detailed information, see Zuora MCP server. Users can view data or perform actions only when their existing Zuora permissions allow it. Zuora AI does not bypass permissions, segregation of duties, or approval workflows.

Zuora AI services communicate with Zuora systems through private VPC connections rather than over the public internet. Zuora AI uses the existing OneID and OAuth 2.0 authentication framework through the Zuora API Gateway to authenticate requests and enforce tenant- and role-scoped access.

Tenant-level AI access

A user with the OneID Organization Admin role controls AI access for each tenant in Zuora OneID Admin. Tenant-level settings determine the maximum AI capability that is available to the tenant.

The following tenant-level permission modes are available:

ModeDescription
OffZuora AI is disabled for the tenant. No read or write activity is available.
Read-OnlyZuora AI can answer questions, query data, generate insights, and display summaries. It cannot make changes to Zuora data.
SupervisedZuora AI can perform read actions and can propose actions that modify Zuora data. Write actions require explicit user approval before they are executed.

For more detailed information, see Supervised mode for Zuora AI.

Impact on MCP: Supervised exposes read and write tools. Per-action approval for writes that are performed through MCP is enforced by the connected third-party tool, not by Zuora. For more detailed information, see

About Zuora MCP and customer responsibilities.

Only users with the OneID Organization Admin role can change the tenant-level AI permission mode.

The tenant-level AI mode also determines whether Zuora MCP exposes read-only or read-write tools when it is connected to third-party AI tools.

For information about the current rollout schedule and how to opt out, see Supervised mode for Zuora AI.