Permissions & security
What assistants can and can’t do, how sign-in works, and how teams and limits apply.
What assistants can do#
| With your approval, assistants can | Assistants can never |
|---|---|
| See your creators, uploads, posts, calendar and statistics | See your password or sign in as you elsewhere |
| Upload content, create, schedule, edit and cancel posts, only if you tick Allow changes | Pay, change your plan or touch billing |
| Import a file from a public HTTPS link | Connect or remove Instagram accounts |
| Read your plan, quota and free slots | Change security settings or reach another workspace |
How sign-in works#
- You sign in on Toolies, not in the chat. The connection uses OAuth 2.1 with PKCE: the assistant receives a temporary access key tied to your approval, never your password.
- Access keys are short-lived. They expire after an hour and renew automatically while you use the assistant; after 90 days without use, it asks you to sign in again. Each renewal replaces the previous key, and reusing an old one disconnects the assistant.
- You stay in control. See and disconnect assistants on the MCP page of your dashboard. Resetting your password disconnects every assistant at once.
- The same rules as the app. Plan limits, the monthly quota, account checks and the activity log apply to everything an assistant does.
Teams#
When someone on a team connects an assistant, Toolies asks which workspace it should work in. The assistant can only do what that person’s role allows there, checked again on every request: changing someone’s role takes effect without reconnecting.
| Role | What their assistant can do |
|---|---|
| Owner | Everything in the tools reference: upload content, plan, schedule, edit and cancel posts. |
| Manager | Everything in the tools reference: upload content, plan, schedule, edit and cancel posts. |
| Assistant | Everything in the tools reference: upload content, plan, schedule, edit and cancel posts. The usual role for VAs. |
| Viewer | Look only: calendar, posts, creators and statistics. Changes are refused. |
Removing someone from the team, or their leaving it, disconnects any assistant they connected to that workspace.
An assistant acts with your access. Connect only assistants you trust, and read its plan before confirming large changes.
Limits#
| Limit | Value |
|---|---|
| Posts per month | Your plan’s quota, shared with the dashboard |
| Scheduling window | Up to 90 days ahead |
| Posts per request | Up to 50 at once with schedule_posts |
| Videos | MP4 or MOV, H.264 or HEVC, 3 seconds to 15 minutes, up to 4K, 100 MB |
| Photos | JPEG, PNG or WebP, 100 MB |
| Storage | From 2 GB (Free) to 200 GB (Scale) per workspace |
| Requests | 240 per minute for each connected assistant |