# Permissions and safety

A connected assistant acts as you. It is not a separate user with its own
permissions, and it cannot be granted more than you have.

## Two limits, both applied

Every tool call is checked twice:

1. **The connection's access.** A read-only API token, or a connector granted
   read-only access, can never write — whatever it is asked to do.
2. **Your account role.** A read-only role stays read-only through an
   assistant, exactly as it does in the web UI.

The narrower of the two wins. A read & write token held by someone with a
read-only role still cannot change anything.

| | Read-only role | Editing role |
|---|---|---|
| **Read-only connection** | Read | Read |
| **Read & write connection** | Read | Read and write |

Give a connection read-only access unless it needs to change things. It is the
one limit that holds even if an assistant misreads what you asked for.

## One account, and only one

A connection reaches exactly one account:

- An **API token** is bound to the account it was created in.
- A **connector** you approve in Claude.ai or ChatGPT is bound to the first
  account your user belongs to. The approval screen names it.

There is no cross-account addressing. An id from another account reads as "not
found", not "forbidden" — the connection cannot tell that the record exists.

A token also stops working once the person it belongs to leaves the account it
is bound to, and when it expires.

## Everything is recorded

- **Changes are audited.** Anything an assistant creates, updates or deletes is
  written to the audit trail against your name, alongside changes you made
  yourself.
- **Downloads are audited.** Exporting a questionnaire or RFP through an
  assistant is recorded, the same as downloading it from the web UI.
- **Calls are tracked.** Which tool ran, whether it succeeded and how long it
  took are recorded for support and usage reporting. What you asked is not:
  question text, filenames and file contents stay out of the analytics.

## Deletes are recoverable

Every delete is a soft delete. A record an assistant removes leaves active use
but is not destroyed — it can be restored in the web UI, and support can restore
it later. That is a safety net, not a licence: an assistant can delete a lot of
things quickly, and restoring them one by one is slower than deleting them was.

**Read-only is the sensible default:** Connect read-only first. Grant write access when you have a reason to — a
questionnaire you want started from a spreadsheet, knowledge base items you want
drafted — and consider a separate read-only token for the assistant you use for
day-to-day lookups.

## Limits

The server accepts up to 300 calls every five minutes per token. Ordinary
conversation stays well inside that; an assistant paging through a large
knowledge base can reach it, in which case calls are refused until the window
resets.

An active ResponseHub subscription is required. Without one, tools return a
message saying so rather than partial data.

## If a connection stops working

| What you see | Usually means |
|---|---|
| The client cannot authenticate at all | The token was revoked, rolled or has expired; or the connector's approval was never completed. |
| Reads work, writes are refused | The connection or your role is read-only. |
| Everything is refused with a subscription message | The account has no active subscription. |
| Calls suddenly fail after working fine | The rate limit was reached — wait, then retry. |

## Next steps

- [Connecting Claude.ai and ChatGPT](/help/mcp/connecting-claude-and-chatgpt/)
- [Connecting Claude Code and Cursor](/help/mcp/connecting-claude-code-and-cursor/)
- [Roles and permissions](/help/managing-your-team/roles/)