Approvals, permissions, and safety
Magister uses two layers of control: connector scopes decide which kinds of MCP tools are available, and the brand's Permissions policy decides which external actions must stop for review.
Read first — profile, plan, audit, AI-visibility, asset, research, social-analytics, and integration-discovery reads are available with the default read scope. Running jobs or changing anything requires an opt-in scope.
Immediate confirmation — publishing live content, sending email, spending money, deleting an asset, and other destructive actions require the relevant scope and an immediate user confirmation. Ad campaigns created through Connect start paused; activating spend is a separate explicit action. Paid ads and media generation use separate scopes that even Full access does not silently include.
Permissions panel — open Permissions in the right-hand panel. Pending shows requests waiting for a decision; History shows allowed, denied, running, successful, failed, and expired actions from Connect, Agent, workflows, and Slack. Open a request to review the exact destination, content, schedule, campaign, repository, or other details.
Approve or deny — approve to let the displayed action run, or deny it. A denial can include optional feedback for the agent, and the note remains in permission history rather than being sent to the external service.
Returning to the assistant — a high-risk MCP tool can return an operation ID and Magister review link. After you decide, the assistant polls the approval status and receives a redacted result rather than the raw action token or sensitive arguments.
Ask-before categories — brand admins can require approval for email, social publishing, content publishing, paid ads, code and pull requests, destructive actions, and other external changes. Turning a category off allows matching actions to run without asking. Allow all requires a strong confirmation; provider authorization, budgets, ownership checks, and other guardrails still apply. Paid spend and destructive approvals require a brand admin.