AI in Leed

AI in Leed is not one feature with one switch. There are five separate surfaces, three of them things you point a client at, and they differ less in what they know than in who is authenticating. Your own team signing in to the CMS, your team’s AI tools connecting from outside, your readers’ AI tools connecting to your published documentation, and anonymous agents reading your public posts are four different callers with four different ceilings. Pick the surface by the caller and the rest follows.

MCP, tool, resource, consent and audience-bound token are used on this page in their Model Context Protocol senses; the glossary defines each one if any of them is new.

flowchart LR
  T["Your team<br/>signed in to Leed"]
  R["Your readers"]
  P["Anyone<br/>including agents"]

  E["AI inside the editor<br/>session · writes"]
  A["Leed Assistant<br/>session · writes · Administrator only"]
  O["Operator MCP<br/>OAuth + browser consent · writes"]
  D["Docs MCP<br/>email + one-time code · read-only"]
  S["Site AI agent<br/>no sign-in · read-only"]

  T --> E
  T --> A
  T --> O
  R --> D
  P --> S

The five surfaces

AI inside the editor

The helpers that live on the screens you already work on: the AI Assistant panel opened from the editor toolbar or with Mod + J, and the sparkle buttons that write a page summary, propose keywords, describe an image for alt text or generate a feature image.

There is nothing to connect and nothing to authorize. These run inside your signed-in CMS session, and access is decided by the ai:write privilege — Content Writer and up — alongside the ordinary page:write permission on the page you are editing. They act on the draft in front of you and nowhere else. The drafting shortcut and the metadata sparkles are documented with the editor screens that host them, in AI in the editor.

The Leed Assistant

The agentic one. It does not just answer questions about your workspace — it calls tools against it: searching pages, drafting content, creating campaigns, querying analytics and rendering a chart in the conversation. It lives on the Chat tab of the rail and on the page editor’s right-rail AI tab.

Because it can act, it is the most tightly restricted surface in the product: only an Administrator can use it. That is a permission boundary, not a plan gate — no upgrade grants it, and see roles and permissions for what else that role carries. Anything destructive it tries — publishing, deleting — stops and waits for you to press Approve. Leed Assistant is the full account of its tools, its two risk tiers and its approval card.

The Operator MCP

Your workspace as an MCP server, at https://app.leed.ai/mcp. Point Claude, Claude Code, ChatGPT, Cursor or any spec-compliant client at that one URL, sign in through your browser, and the client works inside your workspace under your own Leed role.

There is no API key, no client secret and nothing to paste — the client registers itself and you approve it on a consent screen. Writes land as drafts and tracked suggestions; publishing and deleting are not on the menu at all. Connecting to the Operator MCP walks the connection, and what the Operator MCP can and cannot do is the honest scope.

The Docs MCP

Your published documentation as an MCP server, served from your own domain rather than from Leed. If you publish docs, your readers can connect their own AI clients to them and get structured search, whole pages and your OpenAPI spec instead of scraped HTML.

Your readers do not need Leed accounts. They verify with an emailed one-time code, and you decide which addresses and domains are allowed in. Every tool is read-only, and the surface always serves your latest published version — publish an update and connected clients see it with nothing to re-sync. Docs MCP: AI access for your readers covers the reader-facing side.

The site AI agent

The public, sign-in-free surface over your published posts — blog, news, articles. It speaks WebMCP, discovered at /.well-known/webmcp, alongside an A2A AgentCard, so browser agents and agent frameworks find your content in a structured form rather than guessing at your markup.

Nobody authenticates. Everything is read-only, and it exposes only content you have already published to the open web. Site AI agent describes its tools and how discovery works.

Which one do I want?

I want to…SurfaceWho signs inRead or writeWhere it runs
Draft and clean up copy on the page I have openAI in the editorYou, already signed in to the CMSWrites the draft in front of youInside the Leed CMS
Ask something to plan, research or act across the whole workspaceLeed AssistantYou, already signed in — Administrator onlyWrites, with destructive work parked for approvalInside the Leed CMS
Let my own Claude / Cursor / MCP client work in my workspaceOperator MCPYou, through a browser OAuth consent screenReads broadly; writes drafts and suggestionshttps://app.leed.ai/mcp
Let my customers’ AI tools read my docs and API referenceDocs MCPYour readers, with an emailed one-time codeRead-only/mcp on your own documentation domain
Make my blog and articles legible to public agentsSite AI agentNobodyRead-onlyYour published site

AI that is not a surface

Two more parts of Leed are powered by AI but are not services anything connects to. They are worth naming here so you do not go looking for them on the pages above — and both behave differently below their tier rather than showing you an error.

Transcription and text extraction. Upload a video, an audio file or a document and Leed transcribes or extracts its text. The extraction itself always runs and the result is always stored; what a plan below Starter changes is retrieval. The transcript and extracted text are stripped out of the asset before it reaches you, while the “a transcript exists” flag is deliberately left in place, so the editor can honestly say a transcript is there and an upgrade reveals it instantly. No error is raised and no 402 is thrown. Transcription and text extraction shows what the editor displays instead.

Recommendations. The related-content widget on your published site is a vector-similarity engine over your own pages. Below Growth the endpoint answers 200 with an empty list rather than an error — so the widget renders nothing at all instead of breaking the page, and there is no message anywhere telling you why. Recommendations covers the behavior and the fix.

The full minimum-tier column for every feature in Leed lives in feature availability by plan.

What every surface has in common

That posture is not a policy statement — it is five enforcement layers, and it is worth knowing which one stopped your call when something is refused. How Leed’s AI is guarded takes them one at a time, from the connected identity down to the audit row.

ESC