Skip to content

Permissions and safety

A connected assistant acts as you. It is not a separate user with its own permissions, and it cannot be granted more than you have.

Every tool call is checked twice:

  1. The connection’s access. A read-only API token, or a connector granted read-only access, can never write — whatever it is asked to do.
  2. Your account role. A read-only role stays read-only through an assistant, exactly as it does in the web UI.

The narrower of the two wins. A read & write token held by someone with a read-only role still cannot change anything.

Read-only role Editing role
Read-only connection Read Read
Read & write connection Read Read and write

Give a connection read-only access unless it needs to change things. It is the one limit that holds even if an assistant misreads what you asked for.

A connection reaches exactly one account:

  • An API token is bound to the account it was created in.
  • A connector you approve in Claude.ai or ChatGPT is bound to the first account your user belongs to. The approval screen names it.

There is no cross-account addressing. An id from another account reads as “not found”, not “forbidden” — the connection cannot tell that the record exists.

A token also stops working once the person it belongs to leaves the account it is bound to, and when it expires.

  • Changes are audited. Anything an assistant creates, updates or deletes is written to the audit trail against your name, alongside changes you made yourself.
  • Downloads are audited. Exporting a questionnaire or RFP through an assistant is recorded, the same as downloading it from the web UI.
  • Calls are tracked. Which tool ran, whether it succeeded and how long it took are recorded for support and usage reporting. What you asked is not: question text, filenames and file contents stay out of the analytics.

Every delete is a soft delete. A record an assistant removes leaves active use but is not destroyed — it can be restored in the web UI, and support can restore it later. That is a safety net, not a licence: an assistant can delete a lot of things quickly, and restoring them one by one is slower than deleting them was.

The server accepts up to 300 calls every five minutes per token. Ordinary conversation stays well inside that; an assistant paging through a large knowledge base can reach it, in which case calls are refused until the window resets.

An active ResponseHub subscription is required. Without one, tools return a message saying so rather than partial data.

What you see Usually means
The client cannot authenticate at all The token was revoked, rolled or has expired; or the connector’s approval was never completed.
Reads work, writes are refused The connection or your role is read-only.
Everything is refused with a subscription message The account has no active subscription.
Calls suddenly fail after working fine The rate limit was reached — wait, then retry.