No user access added by admin is the default state of the Who can access setting. It means no rule has been configured yet, so the ability or MCP server is locked to administrators only.

Who gets in
- Administrators — always allowed.
- Everyone else — denied.
When to use it
Leave a resource on this setting when it should stay admin-only — while you’re still testing a new ability, or for anything you never want non-admins to reach. Because it’s the default, a brand-new ability or server is safe out of the box: nothing is exposed until you deliberately open it up.
Ready to open it up? Switch the dropdown to Everyone, or to a specific rule like WordPress Role, Users or WordPress Capability.