Skip to content

Permissions and approvals

Connecting an assistant never gives it unrestricted access to Stenz. Every call is checked against several independent controls.

  1. Subscription: the artist account must include the requested product capability.
  2. OAuth permission: the connection must have the required scope.
  3. Connection policy: Stenz can restrict tools, forms, client details, media, frequency, and time windows.
  4. Ownership: the resource must belong to the connected artist workspace.
  5. Risk level: writes may require a preview, confirmation, or approval inside Stenz.

Grant the smallest useful set of permissions. Add client details or write access only when the workflow needs them.

Level Meaning What happens
R0 Read Runs directly when the connection policy allows it.
R1 Private or reversible write Stenz prepares a bounded change and may request confirmation.
R2 Meaningful or client-visible write A precise preview and explicit confirmation are required.
R3 Financial, legal, or destructive action The action remains pending until approved with a recent session inside Stenz.

An approval in ChatGPT or Claude never replaces the Stenz approval screen.

Client contact details and media use separate permissions. A connection without full client-detail access cannot use search results to infer hidden names, e-mail addresses, phone numbers, or social identifiers.

  • Pause in Stenz → AI assistants to stop calls immediately while keeping the connection configuration.
  • Revoke in Stenz first to invalidate the token family and rotate the connection version.
  • Remove the connector from ChatGPT or Claude after revoking it in Stenz.

Removing only the provider-side connector is not proof that Stenz authorization was revoked.