Least useful access
Choose the narrowest permission that still allows the agreed workflow. Read-only provider scopes are the default when a workflow only reads.
Security and control
A useful setup starts with understandable permissions: which tools can read information, which can change it, who approves actions, how access is revoked, and what the record shows afterward.
Choose the narrowest permission that still allows the agreed workflow. Read-only provider scopes are the default when a workflow only reads.
Public visitors, customer staff, connected agents, and InstallAI support do not share one permission model or a general-purpose credential.
External sends, record changes, device changes, purchases, and other commitments require exact, reviewable proposals where appropriate.
A connection needs an owner, expiration or review point, revocation path, and a way to stop queued work that depends on it.
What is live today
This launch serves public pages and a keyless, read-only catalog. It contains no customer database, private connector credentials, admin assistant, live booking, payment, or authenticated agent actions.
This is the required design boundary for a future private product, not a claim of completed implementation.
Questions to ask
The answers belong in the project scope and the operating runbook.
Specific sources, fields, classifications, and retention.
Exact operations and records—not a generic “write” promise.
The person accountable for each consequential action.
Principal, tenant, decision, target, time, and result—without secrets.
Provider grant, queued work, sessions, and approvals.
Denial, timeout, uncertain result, recovery, and owner contact.