Skip to main content
Access depends on your company membership, provider permissions and any client consent. Connecting a service does not make all its data available to every person or every AI client.

Keep context appropriate

Confirm the company and store before working. Use supported account roles and sharing controls for commercially sensitive information. A private Readout and a shared company Readout have different audiences. Brand context should contain information useful for company work. Avoid saving unnecessary personal data or credentials as broad company memory. A source or policy correction should remain distinguishable from an inferred suggestion.

Shopify connector data

The Shopify connector separates catalogue access from optional order and customer permissions. Order or customer functionality depends on merchant grants and applicable Shopify approval. Check the current grant before requesting customer data. The supported Shopify connector masks customer email addresses before exposing them to an AI assistant or record and does not read customer phone numbers. This protection applies to that connector path. Check other services and uploaded documents separately for personal data.

External AI clients

An MCP grant controls the data classes that a connected client can use. Read the consent screen and the client’s own data-handling terms. Giving catalogue access does not mean giving brand or analytics access automatically. Never pass a connection secret through the model. The supported connector uses bearer authentication and grants; a model prompt is not a credential store.

Check access before an investigation

Open Integrations in the correct company and inspect the relevant connection. Check whether the provider is connected, whether its permissions cover the task and whether the account supports the operation. A catalogue question, an order enquiry and a customer lookup can require different access. If you are using an external AI client, inspect the client consent as well. For the Shopify connector, the connection overview tool describes the grant’s data classes, write enablement, provider scopes and usage. A missing capability may reflect consent or provider permission; retrying the same request does not add either.

Keep source data and broad context distinct

A customer enquiry may need specific order evidence. That does not make a full customer profile useful as a company-wide memory entry. Keep the minimum relevant facts with the supported enquiry and work record, and avoid duplicating personal data in unrelated notes. Brand policies and explicit instructions can be shared business context. An inferred preference or a source summary is different from an owner-confirmed instruction. If the sources conflict, identify the disagreement and correct the underlying material through the supported control. Do not use a convenient summary to overrule the actual policy. Before sharing a Readout, check that the intended audience should see its figures and supporting context. A new Readout is private to its maker; sharing moves it into the company audience. Check commercially sensitive figures before sharing them.

What happens when you revoke access

Revocation or disconnection changes future access through the affected grant or provider link. It does not make a previously sent reply unread, remove copies held by another service, or erase every work record already retained under the applicable policy. Treat access recovery and deletion as different tasks. To recover access, use the supported account/provider flow and verify the new grant before resuming work. To request deletion, follow the applicable privacy process and identify the account or work concerned without posting raw data into a general conversation. For an external client, check both BYOM’s grant controls and the client’s own account and retention terms. For deletion from an independent client’s systems, use that client’s own process.

If access is unexpectedly broad or missing

Stop the affected request and record the company, task reference, visible error or grant state and approximate time. Do not include the token or full result payload in a support message. If a provider change has an uncertain result, check the receipt and provider state before retrying. If data access is refused, address that permission boundary rather than trying another company or client to bypass it. Reviewed 2 October 2026.