AI access control

Read, write, delete.
You decide, per integration.

Let the AI read Salesforce opportunities but never delete a contact. Keep QuickBooks read only. Every call it makes is logged: who asked, what it touched, and when.

SOC 2 and HIPAA. Reports in the Trust Center.

Access rules

5 integrations · RevOps workspace

Tool

Read
Write
Delete

Salesforce

Opportunities and accounts. Never deletes a contact.

Read
Write
Delete

QuickBooks

Invoices, P&L, balance sheet. Read only.

Read
Write
Delete

HubSpot

Deal stages only. No contact changes.

Read
Write
Delete

PostgreSQL

analytics schema. No writes to production.

Read
Write
Delete

Google Sheets

Writes to the Weekly pipeline sheet only.

Read
Write
Delete

Activity log

Every call recorded

Read 42 opportunities in Salesforce

Maya

9:12am

Update deal stage in HubSpot

Maya

9:13am

Delete contact in HubSpot · blocked by rule

Maya

9:14am

Read invoices in QuickBooks

Monday report, scheduled

9:14am

A RevOps workspace. Deal stages can move in HubSpot, contacts cannot be deleted.

What you get to decide.

The fear is specific: it changes or deletes something it should not, and nobody finds out. Each control below answers one half of that.

Finer than read or write.

Rules apply per integration and per object inside it: read opportunities in Salesforce, never delete a contact, write to one spreadsheet only. A warehouse rule can go down to a table, a column, or a row filter.

One rulebook for chats and schedules.

A rule set once covers every conversation and every scheduled run in that workspace. The Monday 6am report cannot do anything the analyst asking live could not.

Rules that end on their own.

Open a warehouse table for the quarter close and set the rule to end on Friday. Keys carry an expiry too, so temporary access stays temporary.

How it works, in the order you will do it.

1

Connect the tool.

Approve access on the tool's own consent screen. Salesforce, QuickBooks, HubSpot, PostgreSQL, Google Sheets, and 100+ more.

2

Set the rules.

Pick read, write, and delete per integration, then tighten by object where it matters. Set them org wide, or per workspace.

3

Let it run.

Ask questions, build dashboards, schedule the Monday report. Every call checks the rules before it reaches the tool.

4

Read the log.

Who asked, what was called, what was passed, and when. Open it per workspace in the app.

The specifics.

What a careful reviewer scrolls to first. Real rules, what the log holds, and who can change what.

Rules, with real examples.

Every rule names an integration, what inside it, and an effect. The same rule can be org wide or scoped to one workspace.

Integration and rule

Effect

Salesforce · Read opportunities and accounts

Allowed

Salesforce · Delete any contact

Blocked

QuickBooks · Read invoices, P&L, balance sheet

Allowed

QuickBooks · Create, edit, or void anything

Blocked

HubSpot · Update a deal's stage

Allowed

HubSpot · Delete contacts

Blocked

Google Sheets · Write to the Weekly pipeline sheet

Allowed

Google Sheets · Write to any other sheet

Blocked

BigQuery · Read tables in the analytics dataset

Allowed

BigQuery · Touch any table ending in _pii

Blocked

Org wide rules come first.

An org wide block cannot be loosened by any workspace. An org wide allow can still be tightened inside one.

Inside a workspace, first match decides.

Rules run in the priority you set. Anything no rule mentions falls to the workspace default: allow, or block everything.

Rules can expire.

Give a contractor write access until Friday, or open a warehouse table for the quarter close, and it closes itself.

What the log records.

One entry per call. Scheduled runs write the same entries as a person asking live.

Who asked: the person, or the scheduled run

Which workspace it ran in

The exact call: tool, object, action

The inputs it passed

When, and how long it took

Automations inherit the rules.

A scheduled run executes inside a workspace and carries that workspace's rules. Read only in the workspace means read only at 6am on a Monday. There is no second permission set to keep in sync.

Scoped keys for programmatic access.

Each key carries its own rules, an expiry date, and a default of allow or block when nothing matches. Revoke a key and its access ends with it, and every call it ever made is still in the log.

Where it runs is a separate question.

Questions reviewers ask.

Set the rules, then let it work.

Connect a tool, set read, write, and delete, and watch the first call land in the log.

Flat pricing, not per viewer.

See pricing →