Skip to content

Permissions and trust

Connecting an assistant to Vaam gives it access to your account. This page says exactly how much — what it can read, what it can change, what it can never reach, and how to take the access away. If you are reviewing Vaam for your security team, this is the page to read.

The short version: a connected assistant can do what you can do, and nothing more. It signs in as you, it is limited to your own data unless you ask about your team, and it can be cut off at any time.

By default, every tool returns your own data only. When your assistant lists sequences, prospects, videos, tasks, or issues, the list contains your records and no one else’s — even when you share a team.

Your team’s data is included only when you ask for it. Four kinds of list can widen to the whole team, and only on request:

Ask aboutAssistant can widen to the team
SequencesYes
ProspectsYes
Prospects’ progress in sequencesYes
Issues affecting outreachYes
VideosNo — always yours only
TasksNo — always yours only
Account totals and limitsNo — always yours only

“On request” means an explicit question about the team, such as “how many prospects is my team working right now”. A question about your numbers stays about your numbers.

There is one nuance worth naming. When your assistant opens a single record by its ID — one prospect, one sequence, one video — it can open that record if you own it or if it belongs to your team. This mirrors the Vaam web app, where you can already open a teammate’s prospect. It cannot open a record belonging to anyone outside your team, in any circumstance.

Writing is a separate set of permissions from reading, and you see the full list before you approve. A connected assistant can:

  • Pause and resume a sequence.
  • Add prospects to a sequence, correct a prospect’s contact details, and remove a prospect.
  • Pause, resume, or permanently stop outreach to one person.
  • Mark an issue as resolved or dismissed.
  • Create a video and finish uploading it.
  • Change your AI outreach settings: your ideal customer profile, company details, offering, and message language.

One consequence to know about: if you are a team owner or team admin, changing the AI outreach settings also changes them for every member of your team. That is how those settings work in Vaam generally — the assistant is not doing anything special — but it is easy to forget when you are chatting rather than clicking.

An assistant never sends outreach itself. It starts and stops the work; Vaam performs it, on your normal schedule and within your normal limits.

Tools that only read are labelled as read-only, and tools that change data are labelled as writing, with a further flag on the ones that overwrite or remove something. Assistants show these labels, which is why Claude asks you to confirm a change but not a lookup.

No matter what you approve, a connected assistant cannot:

  • See data belonging to another team, or to a Vaam customer who is not you.
  • See your password. You type it into Vaam’s own login page, in your own browser, never into the assistant.
  • Reach billing, invoices, or payment details.
  • Reach Vaam’s internal support and administration tools. Those live on a separate address, described below.
  • Do anything after you disconnect it.
  • Grant itself more than you approved. Permissions can be narrowed later but never widened, and they are checked against your live account rather than frozen at the moment you approved — so if your role in Vaam changes, the connection follows.

The approval screen lists permissions in plain terms. This is what each one covers:

On the approval screenWhat it allows
Read sequencesSee your sequences, their steps, and their stats
Write sequencesPause and resume a sequence
Read prospectsSee your prospects and their details
Write prospectsAdd prospects to a sequence, correct their details, remove them
Read enrollmentsSee where each prospect is in a sequence
Write enrollmentsPause, resume, or stop outreach to one person
Read videosSee your video recordings and their view stats
Create videosUpload a new video
Read statsSee your counts, totals, and account limits
Read work itemsSee issues affecting your outreach
Write work itemsMark an issue resolved or dismissed
Read user informationSee your name, email, and account type
Read team informationSee your team’s name, size, and connected integrations
Read settingsSee your AI outreach settings
Write settingsChange your AI outreach settings

Two of these lines use the word enrollments. It means a prospect’s progress through a sequence — the same thing the Vaam app shows you on a sequence page.

If you approve without the assistant asking for anything specific, you grant this whole list. An assistant that asks for a shorter list gets only what it asked for.

An API key carries the same permissions, except that you tick them yourself when you create the key. A key that only needs to read can be created with no write permissions at all. Permissions cannot be added to a key after the fact — you create a new key instead.

You can end access at any time:

  • Remove the connector in your assistant. See Disconnecting for where that is in each app. This deletes the tokens the assistant was holding, so it cannot sign in again.
  • Delete the API key under Settings → API. The key stops working immediately.
  • Email support@vaam.io if you cannot reach the assistant, or you think a connection has been misused. We can cut it off from our side.

Two details for a security review. A renewal token is single-use: it is replaced every time it is used, and if an old one is ever presented again, the whole connection is revoked immediately rather than given the benefit of the doubt. And an access token expires one hour after it is issued, which bounds how long a token that was already in flight can keep working after access ends.

Nothing in your Vaam account changes when access ends. Anything the assistant already did stays done — a paused sequence stays paused until you resume it. You can see what it did in your normal sequence and prospect history, because an action taken through an assistant is recorded the same way as an action taken in the Vaam app.

Vaam runs a second MCP address for its own support staff, at a different URL. It is not part of this documentation and it is not available to customers.

It is genuinely separate, not the same address with a flag set. Access granted for the normal address is rejected at the administration address, and the reverse is also true. Approving a connection for your assistant cannot, by any route, produce access to internal tools.

Vaam never sends your data to Claude, ChatGPT, or any other assistant on its own. It travels there because you connected the assistant, and only in answer to the question you asked — the same path it would take if you opened the Vaam app and copied the answer into a chat yourself.

Once it arrives, that data is handled by the assistant’s provider — Anthropic for Claude, OpenAI for ChatGPT — under their terms, not Vaam’s. Choose which assistants you connect with the same care you would apply to any other tool that reads your customer data, and check your provider’s data retention and training settings. See the AI assistants section of Vaam’s Privacy Policy for Vaam’s own position.

Vaam’s handling of your data is unchanged by connecting an assistant. See Personal Data Management, GDPR, and Sub-processors.

Questions about a connected assistant, or about anything it did on your behalf: email support@vaam.io.

For Vaam’s full data handling commitments, see the Privacy Policy and the Terms of Service.