What the connector will not do
The things no key and no sign-in can make the connector do, and where each one stops.
The connector cannot send anything, approve anything, start a campaign, or delete anything. These limits are in the code, not only in the instructions given to the assistant.
| It will not | What happens instead |
|---|---|
| Send an email, a LinkedIn invite or a message | No tool does. Sending happens in the app, or for LinkedIn in your own browser through the Chrome extension |
| Start or resume a campaign | start_campaign and linkedin_campaign_activate prepare a Start card. You press Start in the app, and its launch checks must pass. If they fail, the card says why and there is nothing to approve |
| Approve a card | pending_approvals lists what is waiting. Approving is only possible from the signed-in app. No scope grants it |
| Delete a record, list, campaign or person | Tools archive or pause instead. A name that reads as deleting or cancelling is refused when the server starts |
| Cancel a calendar event | It offers to reschedule an event Adapt created |
| Create a key | Keys need a signed-in app session, so a leaked key cannot make another |
| Touch LinkedIn from our servers | LinkedIn tools only queue work for your own Chrome extension |
| Connect your mailbox, LinkedIn posting or calendar | Connecting stays in the app. connections_status only reports whether they are connected |
| Return a full contact list for the whole book | Search is masked and capped by page, depth and daily and monthly rows |
| Say how a record was judged or where a fact came from | Tool results are cleaned on the way out. Counts and dates may appear, never a source name |
| Act in another organisation | The organisation comes from the account's own membership. No field in a request chooses it |
| Change your plan, password or payment details | No tool does |
What a direct write can do
A few tools make a change straight away when the key has the write permission: lists_create, lists_add, lists_archive, searches_save, campaigns_create, campaigns_add_people, campaigns_pause, campaigns_archive, campaigns_unarchive, and linkedin_campaign_enqueue_leads. Each is undoable: lists and campaigns are archived rather than removed, a campaign can only be paused, and queueing people on a LinkedIn campaign never starts it.
What about reveal and export?
reveal_lead and export_list prepare cards. The credit or the allowance is used when a person approves. The public website says the connector cannot export. More exactly, it cannot export by itself: it can prepare an export card that you approve in the app.
Untrusted text
Text in results that anyone could have written, such as a business name, is defanged before it reaches the assistant so it cannot pass as an instruction. The assistant is also told to treat it as data. This lowers the risk. It does not remove it, so keep a person in the loop for anything that matters.