Security and control

Know what connects. Decide what happens.

A useful setup starts with understandable permissions: which tools can read information, which can change it, who approves actions, how access is revoked, and what the record shows afterward.

1

Least useful access

Choose the narrowest permission that still allows the agreed workflow. Read-only provider scopes are the default when a workflow only reads.

2

Separate identities

Public visitors, customer staff, connected agents, and InstallAI support do not share one permission model or a general-purpose credential.

3

Approval before consequence

External sends, record changes, device changes, purchases, and other commitments require exact, reviewable proposals where appropriate.

4

Revoke and recover

A connection needs an owner, expiration or review point, revocation path, and a way to stop queued work that depends on it.

What is live today

A public site, not a private customer platform.

This launch serves public pages and a keyless, read-only catalog. It contains no customer database, private connector credentials, admin assistant, live booking, payment, or authenticated agent actions.

✓
Public service catalogOnly owner-approved, intentionally public fields.
✓
Read-only methodsGET, HEAD, and CORS preflight only.
✓
Local planning formBuilds a brief in the browser and does not transmit it.
Future implementation gate
Identity + membershipVerify principal, tenant, role, and client
Policy + proposalCheck tool, object, scope, risk, and exact payload
Approval + receiptRecheck current permission, execute once, and record the result

This is the required design boundary for a future private product, not a claim of completed implementation.

Questions to ask

Before a tool receives access.

The answers belong in the project scope and the operating runbook.

01

What can it read?

Specific sources, fields, classifications, and retention.

02

What can it change?

Exact operations and records—not a generic “write” promise.

03

Who approves?

The person accountable for each consequential action.

04

What is logged?

Principal, tenant, decision, target, time, and result—without secrets.

05

How is it revoked?

Provider grant, queued work, sessions, and approvals.

06

How does it fail?

Denial, timeout, uncertain result, recovery, and owner contact.