Skip to main content
A connected AI client can only do what you approved on the consent screen. Access comes in six scopes, and each scope unlocks a specific set of actions — nothing more.

The six scopes

Read conversations is the only scope a Member can grant. Everything else needs an Admin. On a Member’s consent screen the Admin-only rows appear locked, with an admin only chip, and are not granted even if the client asked for them.
Scopes are all read-only except Create & manage AI agents. Without that scope, a connected assistant cannot change anything in your workspace.

What the assistant can actually do

Each scope maps to a set of named actions — “tools” in AI-client language. You will occasionally see these names in your client’s activity log, so here is what each one is.

Workspace and identity

Available to every connection, no scope required.

Channels — requires Read channels

AI agents — requires Read AI agents

AI agents — requires Create & manage AI agents

These four are the only write actions in the whole set, and they act on live configuration immediately — an agent created, changed or deleted by an assistant is created, changed or deleted for real. Ask an assistant to show you an agent’s current configuration before you ask it to change anything.
An assistant creating an agent can set the same things you would set in the app, including the Effort level — the low, medium or high tier that decides how much reasoning the agent applies and how many credits a conversation costs. It cannot pick a provider or a model; the platform handles that. See Creating an agent.

Conversations — requires Read conversations

Billing — requires Read billing

Automations — requires Read automations

Things worth knowing

  • Long lists arrive in pages. An assistant asking for hundreds of conversations receives them in batches and fetches the next page as needed. You may see it work through a large result set in steps.
  • A missing scope is a clean refusal, not a failure. Calling something outside the granted scopes returns a “forbidden” answer, and a well-behaved assistant will tell you it lacks the access rather than retrying.
  • Everything is limited to your own workspace. There is no way for a connected client to reach another customer’s data.
  • Scopes cannot be edited after the fact. To change what a client may do, revoke it and connect again — see Connecting an AI client.

Next steps

Connecting an AI client

Setting up a connection and revoking it later.

AI connections overview

What MCP is for and where the page lives.