AI Dispatch
The wirewireAug 21, 2026

Linear centralizes MCP agent access through Okta identity; site names no liability cap or SLA terms

Admins can now manage which agents and employees reach Linear through the Model Context Protocol centrally, tied to Okta identity, per a changelog reviewed by AI Dispatch. Linear's data terms disclose SOC 2 Type II certification and customer audit rights, but no liability cap, SLA or third-party evaluation.

Linear, the project-management platform increasingly used by AI coding agents through the Model Context Protocol, has centralized how organizations grant those agents access to its system. "Admins can manage access centrally, without requiring employees to sign in or authorize Linear individually," according to a changelog entry on Linear's site reviewed by AI Dispatch.

Access under the new setup is tied to enterprise identity rather than per-user consent. "Linear verifies their identity through Okta and applies their existing Linear permissions," the changelog states, meaning an agent or employee's Linear access follows whatever role Okta already assigns them, set once by an administrator rather than negotiated tool-by-tool.

That is the kind of centrally enforced access control AI Dispatch's trust-gap rubric scores under runtime governance. Linear's separate data processing agreement, also reviewed by AI Dispatch, addresses two other dimensions of that rubric. On compliance, it states the company "has completed its SOC2 Type II certification." On audit rights, it gives customers the ability to inspect Linear's own records: "Customer shall, with reasonable notice to Linear, have the right to review, audit and copy such records at Linear's offices during regular business hours."

The same agreement sets a standard for moving customer data across borders, permitting transfers only where "the protection afforded by the laws of the country of the Data Importer to data subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK." It also indemnifies Linear rather than the customer for certain data claims: a customer "shall indemnify Linear from all claims and losses in connection therewith" if it supplies personal data improperly.

Three items on AI Dispatch's rubric are absent from Linear's public materials, per this review: a liability cap, a service-level-agreement commitment, and an independent third-party evaluation of its security or AI controls. Linear also does not state publicly whether its audit trail is tamper-evident. Those are absences in what the company has published, not denials — enterprise customers may negotiate terms not posted publicly.

Sources 6

  1. Admins can manage access centrally, without requiring employees to sign in or authorize Linear individually.
    linear.app · checked Aug 20, 2026
  2. Linear verifies their identity through Okta and applies their existing Linear permissions.
    linear.app · checked Aug 20, 2026
  3. Linear has completed its SOC2 Type II certification.
    linear.app · checked Aug 13, 2026
  4. Customer shall, with reasonable notice to Linear, have the right to review, audit and copy such records at Linear’s offices during regular business hours.
    linear.app · checked Aug 13, 2026
  5. the protection afforded by the laws of the country of the Data Importer to data subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK
    linear.app · checked Aug 13, 2026
  6. shall indemnify Linear from all claims and losses in connection therewith.
    linear.app · checked Aug 13, 2026