Keys and permissions
Read, write, and calling permissions, and how to revoke a key.
A key is how an assistant or a script proves it is you. Three permissions, separately granted, individually revocable.
Manage them at Account → AI Access.
The three permissions
| Permission | Lets it | Default |
|---|---|---|
| Read | See leads, calls, appointments, metrics, and your open times. Change nothing. | On |
| Write | Add leads and book appointments. | Off |
| Place calls | Start real outbound calls to real people. | Off |
Placing calls is never implied by write access. Booking an appointment and dialing a stranger are not the same risk, so they are not the same switch. A key with write access still cannot call anyone.
Start read-only. Add a second key with more when you know what you actually need. Keys cannot be upgraded after creation, on purpose: it means a leaked key's blast radius is fixed at the moment it was made.
Rules that keep this safe
A key can never make another key. You need your login for that. So a leaked key cannot mint itself permanent access, and revoking is always possible from a surface the key cannot touch.
Every key is scoped to one account. There is no key that sees two accounts, including for agencies. Managed clients are reached through the app, not through a master key.
Ten active keys maximum. An account with dozens of keys has either been compromised or lost track, and both are worse than being told to revoke one first.
Revoked keys stay listed. They are marked revoked rather than deleted, so you keep the record of what that key could do and when it was last used. That record is exactly what you want if you ever suspect a leak.
Good hygiene
- One key per place it lives. "Claude on my laptop" and "Claude on my phone" as separate keys means revoking one does not break the other.
- Name it after the place, not the purpose. You will be reading these names in a hurry.
- Check last-used. Every key shows it. A key you do not recognize being used is the whole reason that column exists.
- Revoke what you are not using. Free, instant, and reversible by making a new one.
If a key leaks
- Revoke it in Account → AI Access. It dies immediately, everywhere.
- Check what it could reach. The revoked row still shows its permissions. A read-only key that leaked exposed your lead list. A key with
dialcould have placed calls. - Look at your recent calls if it had
dial. - Make a new one with the minimum permissions you actually need.
- Tell us at support@leadbind.org if you think something was done with it. We can look.
Signing out of the CLI (leadbind logout) removes the key from that machine. It does not revoke it. If the machine is gone or compromised, revoke.
What a key can never do
- See another account's anything
- Reach call recordings or transcripts, at any permission level. See What we send
- Touch billing or payment details
- Create, modify, or read another key
- Change your account settings or delete your account