Choose the right access level.
Every connection has an access level that decides what it can do — read your data, write content, or run checks. Grant the least you need, and raise it later.
You set an access level when you create a token — or when you approve a sign-in connector for claude.ai or ChatGPT. It is the main safety control on a connection: whatever you ask your assistant to do, the connection can only do what its level allows. A read-only connection cannot generate or run anything, no matter how the request is phrased.
The three levels
There are three presets, each a superset of the one before it. The default is Read-only.
- Read-only — the default. Reads everything: your brands, competitors, briefs, AI-visibility, SEO, traffic and content. It spends nothing and returns the full dashboard view. It cannot generate or run anything.
- Content — everything Read-only can do, plus generate social posts and articles, generate a daily brief, approve, schedule or mark content as published, and save a WordPress draft. These actions spend credits per the tool.
- Full — everything Content can do, plus run AI-visibility checks, run SEO and site AI audits, and add and analyse competitors. The highest-spend actions live here.
What each level unlocks
Each capability needs a minimum level. Grant that level or higher, and nothing more.
| Capability | Minimum level |
|---|---|
| Read your data | Read-only |
| Generate content (posts / articles) | Content |
| Generate a daily brief | Content |
| Save a WordPress draft | Content |
| Run an AI-visibility check | Full |
| Run an SEO or site audit | Full |
| Add / analyse a competitor | Full |
Narrow it further
The access level sets the ceiling. Two more limiters sit on top of it, so a connection can do less than its level allows but never more.
- Brand scope. Limit a token to specific brands, so a connection built for one client's workspace cannot touch another's data.
- Daily credit cap. Off by default. When you set one, it caps how much a single token can spend per day, so a runaway request can't drain your balance.
- Team roles still apply. A Viewer teammate's connection is always read-only, whatever level was chosen when the token was made — a read-only member cannot spend through MCP.
You set brand scope and the daily cap when you create the token. See create and manage tokens for the steps.
How to choose
Start with Read-only to explore — ask for your brief, your competitors and your AI-visibility, and see how the assistant works with your data. Step up to Content when you want it to draft posts and articles, generate a brief and save WordPress drafts for you. Reserve Full for a connection you trust to run paid checks and analyse competitors on your behalf.
Prefer several narrow tokens over one all-powerful one. A read-only token for a shared device, a Content token for your own drafting client, and a scoped Full token where you actually run checks is safer than a single Full token doing everything.
A read-only token can't cost you anything and can't change anything — so it's the safe default for a new connection, or for any assistant on a shared device. Raise the level only when a specific task needs it.