Every API token and every connected assistant has scopes: the kinds of thing it may do. On top of that, it can never do more than your role on the account allows: a viewer who connects an assistant gets a read-only assistant, whatever it asked for.
The scopes
| Scope | Allows | Default |
|---|---|---|
read | Look at everything: sites, health, logs, deploys, backups, traffic, domains, DNS, email, invoices, the team | Always |
deploy | Deploy from git, set build steps, approve or roll back releases (with your confirmation) | On |
manage | Site settings (environment variables, PHP or Node.js version), connect a domain, staging, cron, backups and restores, webhooks | On |
dns | Change DNS records, import zones, enable DNSSEC (with your confirmation) | On |
data | Read-only SQL on site databases; write to warehouse databases; dashboards, pipelines and jobs | Off: tick it on purpose |
billing | Propose orders for you to approve (how ordering works); nothing is bought with a token | Off: tick it on purpose |
Who can give which scope
| Role | Can grant |
|---|---|
| Owner | All of them |
| Admin, developer | read, deploy, manage, dns, data |
| Billing | read, billing |
| Viewer | read |
| Site team member | read, deploy, manage, data, for their sites only |
If someone's role changes, the tokens and assistants they connected change with it straight away.
Actions that ask first
A few actions cannot be undone, so an AI assistant must ask you twice: the first call only explains what will happen and returns a short-lived confirmation; the second call, with your yes, does it. (A script using a personal API token is not asked: you decided when you wrote it.) They are restoring a backup over the live site, enabling DNSSEC, dropping a warehouse database, approving a release and rolling back. Restores started from an assistant are finished by you in the portal.
Things only you can do, in the portal
Deleting a site, a domain or a DNS zone; changing a domain's nameservers; creating API tokens; changing the team; and paying. An assistant will send you a link for these.