Documentation

Scopes and permissions

Review Connected agent permissions and disconnect access.

Connected agents receive only the permissions shown on the Appaca approval screen. They require an active paid plan.

To give Appaca tools from another system, see MCP servers.

Available permissions

apps:read — View your apps and their build status

The client can list and inspect apps, check app status, and read app conversations.

apps:build — Create apps and message build agents (spends AI credits)

The client can create apps, send app instructions, and continue after an app asks a question.

apps:write — Edit app details and publish apps

The client can change app details.

A client can request more than one permission.

What Connected agents cannot do

  • Set up or modify connectors
  • Create or change coworkers, Pulses, or Knowledge
  • Delete or archive an app
  • Read or write app code directly
  • Touch billing or workspace administration

The client’s access is also limited by the approving person’s workspace membership and app access.

How access ends

Disconnect it. Workspace owners and admins can go to SettingsConnected agents and select Disconnect.

Workspace access changes. The connection stops working when the approving person no longer has the required workspace or app access.