AI Agent

Agent permission roles: everything, drafts only or read only

Limit what each kind of agent may do on a project: the desktop agent, the Reaudit assistant, Claude or ChatGPT over MCP, and API keys.

Permission roles are off by default (every agent can do everything its user can). Turn them on in Project settings → Agent features → Agent permission roles, then choose a level for each kind of agent.

The levels

  • Everything: no limits.
  • Drafts only: the agent can read data, check drafts and create or edit drafts, but cannot publish, schedule, cross-post, approve a social campaign, open SEO pull requests, submit URLs to Bing, or change live ad accounts (switching campaigns on or off, bids, negative keywords, new ads or campaigns on the ad platforms). Saving a WordPress draft is allowed.
  • Read only: the agent can read and check, but not change anything in the project.

The kinds of agent

  • Desktop agent: the agent in the Reaudit desktop app.
  • Reaudit assistant: the assistant in the web app, including its paid ads tools.
  • MCP clients: Claude, ChatGPT and other apps you connected to Reaudit.
  • API keys: anything using one of your Reaudit API keys.

When an agent is refused

The agent is told the project only lets it prepare drafts (or only read), saves its work as a draft and tells you it is ready to publish. The refusal is listed in Agent activity as blocked, with the reason. Your own edits in the desktop Studio panel are never limited.
Combine with the [approval chain](/dashboard/help?article=approval-chain) to let agents prepare everything while people decide what goes live.
permissionsrolesdraft onlyread onlyaccessagentsmcpapi keyssecurity