Common Permission Sets
Use this as a starting point when creating a role for an integration.| API area | Required access |
|---|---|
| CMS read and write | CMS app access |
| Connect360 read | connect360:conversation:read |
| Connect360 send or create | connect360:conversation:engage |
| Connect360 delete | connect360:conversation:delete |
| Restaurant order feed | restaurant:order:read |
| Form read or submit | API key access to the workspace that owns the form |
| Menu products and categories | API key access to the workspace that owns the menu data |
Recommended Setup
Create one role per integration type. For example:Website CMS Readerfor a marketing site that only reads CMS entries.Website Chat Connectorfor Connect360 chat messages and attachments.Accounting Order Exportfor a tool that reads restaurant order totals.
Full Access
fullAccess works, but it should not be the default for integrations.
Use it only when a trusted backend truly needs broad workspace access and the key is stored securely.