Permissions & scopes
When you connect an assistant, you grant it a set of scopes — fine-grained permissions that control what it can see and change. You choose these on the Zoie consent screen, and you can review them any time in the connection's Permissions tab.
The permission categories
Zoie groups access into four categories, each with separate read and write permissions:
| Category | What it covers | Read scope | Write scope |
|---|---|---|---|
| Leads & contacts | View, create, and update lead/contact records | leads:read | leads:write |
| Conversations | Read messages and call logs | conversations:read | conversations:write |
| Appointments | Book and manage bookings | appointments:read | appointments:write |
| Campaigns | View pipeline and campaign performance | campaigns:read | campaigns:write |
Read vs. write
For each category, the Permissions tab shows one of:
- Read + Write — the assistant can both view and change records.
- Read only — the assistant can view but not change records.
- Write only — the assistant can create/update but not read back (uncommon).
- Not allowed — the assistant has no access to that category.
This always reflects the scopes you actually approved. If you grant
leads:read but not leads:write, the Leads row shows Read only.
Narrowing access at consent
On the Zoie consent screen you can leave out permissions you don't want to grant. For example, you might give a research assistant Read only access to leads and conversations while withholding write access entirely. Grant the least it needs to do its job.
Changing permissions later
Scopes are fixed at connection time — there's no in-place "edit permissions." To change what an assistant can do, revoke the connection (Managing connections) and reconnect, approving the new set of scopes.
Business scope
A connection is also tied to a single business. An assistant connected to one business cannot see another business's data, even if your Zoie account has access to several. To give an assistant access to a different business, connect it again and choose that business at consent.
Connections created before scoped permissions were introduced ("legacy grants") are treated as Read + Write across all categories. If you see that on an old connection and want it narrowed, revoke and reconnect.