Skip to content

Permissions & scopes

Permissions & scopes

What a call may do is the intersection of the principal’s roles, the key’s scope and the organization’s ceiling. It is computed fresh on every call.

The intersection

Text
effective = roles of the principal
          ∩ scope of the key
          ∩ permissions when the key was created
          ∩ API ceiling of the organization
          ∩ AI mandate (personal keys only)

A scope can only take away, never add. When the person loses a role, the key loses it on the next call too.

Resource scopes

Per resource: no access, read, or read and write.
ResourceReadWrite
Contacts · contactscontacts:readcontacts:write
Companies · companiescompanies:readcompanies:write
Tasks · taskstasks:readtasks:write
Documents · documentsdocuments:readdocuments:write
Invoices · invoicesinvoices:readinvoices:write
Time entries · time_entriestime_entries:readtime_entries:write
Webhook endpoints · webhook_endpointswebhook_endpoints:readwebhook_endpoints:write

Families

Consequential actions belong to families. Each one is blocked until you allow it on the key one by one.
FamilyWhat belongs to itAllowing it needs
Deletedeleting recordsan IP rule on the key; 10/min and 300 per day
Moneychanging bookings and amountsan IP rule; level of the AI mandate
Finalize documentsfinalizing invoicesan IP rule; level of the AI mandate
Sendsending invoices and documentsan IP rule; level of the AI mandate
Money runsstarting dunning and payment runsan IP rule; level of the AI mandate

When a family is blocked, the API answers 403 RISK_FAMILY_BLOCKED. There is no confirmation round trip through the API: what needs a confirmation in the web app or through MCP is blocked here. A batch allows no money family (BATCH_FAMILY_NOT_ALLOWED).

IP rule

  • Required for every write scope and every allowed family; without an IP rule a key is read-only at most.
  • Up to 32 networks in CIDR notation, IPv4 at least /24, IPv6 at least /48.
  • Private networks, loopback and link-local are not allowed.
  • A call from outside ends as 401; the owner gets an email and a bell entry at most once per hour.

API level of the organization

LevelEffect
offno call at all, not even reads
readreads only; writes end with 403 FORBIDDEN
onreads and writes along the scopes; needs consent to the terms of use

How the preview module comes first is shown in the matrix under Errors.