Permissions and approvals
Connecting an assistant never gives it unrestricted access to Stenz. Every call is checked against several independent controls.
What limits a connection
Section titled “What limits a connection”- Subscription: the artist account must include the requested product capability.
- OAuth permission: the connection must have the required scope.
- Connection policy: Stenz can restrict tools, forms, client details, media, frequency, and time windows.
- Ownership: the resource must belong to the connected artist workspace.
- Risk level: writes may require a preview, confirmation, or approval inside Stenz.
Grant the smallest useful set of permissions. Add client details or write access only when the workflow needs them.
Risk levels
Section titled “Risk levels”| Level | Meaning | What happens |
|---|---|---|
| R0 | Read | Runs directly when the connection policy allows it. |
| R1 | Private or reversible write | Stenz prepares a bounded change and may request confirmation. |
| R2 | Meaningful or client-visible write | A precise preview and explicit confirmation are required. |
| R3 | Financial, legal, or destructive action | The action remains pending until approved with a recent session inside Stenz. |
An approval in ChatGPT or Claude never replaces the Stenz approval screen.
Sensitive access
Section titled “Sensitive access”Client contact details and media use separate permissions. A connection without full client-detail access cannot use search results to infer hidden names, e-mail addresses, phone numbers, or social identifiers.
Pause or revoke
Section titled “Pause or revoke”- Pause in Stenz → AI assistants to stop calls immediately while keeping the connection configuration.
- Revoke in Stenz first to invalidate the token family and rotate the connection version.
- Remove the connector from ChatGPT or Claude after revoking it in Stenz.
Removing only the provider-side connector is not proof that Stenz authorization was revoked.