Permissions
An AI connection gets exactly the permissions you tick, and nothing else. There are eleven: seven to read and four to propose changes. A connection with none ticked cannot be approved at all.
Seven that let an assistant read
| On the approval page | What it allows |
|---|---|
| View your store identity, install date and portal links | Which store this connection answers for, and your affiliate portal links. |
| View your affiliate program settings and setup status | Cookie window, payout schedule, order tagging, and how far Quickstart has got. |
| View your program configuration, commission rules and coupon codes | Your programs in full, including tiers and the coupon codes tied to affiliates. |
| View your affiliate roster, status, earnings and contact email | Who your affiliates are and how they are doing. Contact email only, never their payout destination. |
| View your conversion records and how each was attributed | Conversions, and why a given order was or was not credited to an affiliate. |
| View your payout history and what you owe each affiliate | Payouts made, amounts outstanding, and who is waiting to be paid. |
| View your dashboard KPIs, leaderboards and click analytics | The numbers on your home page, top-affiliate rankings, and click-through data. |
Four that let an assistant propose changes
Each of these only lets an assistant draft a change. Nothing moves until you approve it on a confirmation page, and then only when the assistant applies it.
| On the approval page | What it allows |
|---|---|
| Propose changes to your app settings | The referral cookie window, store name and support address, payout schedule and payment methods, order tagging, and which emails the app sends you. |
| Propose changes to your program rules and commission rates | A program's name, description and commission rules. Never its status, and never the customer-facing discount. |
| Propose approving or deactivating affiliates | Approving an affiliate issues their discount code and emails them their referral link, so this one has real effects. |
| Propose approving or denying conversions | This changes what you owe, so it is treated as a money-affecting change. |
A propose permission is useless on its own: an assistant also needs the matching read permission to draft that kind of change. Tick Propose changes to your program rules without View your program configuration and no program-change tool appears at all.
A permission you leave unticked is genuinely absent
The server filters the tool list by your granted permissions before the assistant ever sees it. An assistant with only read permissions has no change tools in its list, so it will not propose an action and then fail on it. Calls are checked again when they run, so a stale tool list gets refused too.
Three small tools stay available whatever you tick: the assistant can look up support guidance, ask what this connection is allowed to do, and read general facts about the app. None of them touch your data.
What an AI connection can never do
No permission grants any of the following.
- Release a payout, or mark one as paid. There is no such permission, in any version.
- See an affiliate's payout destination, or any bank or wallet detail.
- See the name, email, address or phone number of the customers behind conversions.
- Create or delete a program.
- Change the customer-facing discount on a coupon.
- Change translations, feature flags, or review targeting.
- Touch billing or your plan.
- Reach another store's data. A connection is bound to the store that approved it.
Narrowing or removing permissions later
Untick permissions any time from Edit on the connection, or cut access with Revoke. A narrower set takes effect on the assistant's next request. See Managing connections.