Permissions and trust
Connecting an assistant to Vaam gives it access to your account. This page says exactly how much — what it can read, what it can change, what it can never reach, and how to take the access away. If you are reviewing Vaam for your security team, this is the page to read.
The short version: a connected assistant can do what you can do, and nothing more. It signs in as you, it is limited to your own data unless you ask about your team, and it can be cut off at any time.
What it can see
Section titled “What it can see”By default, every tool returns your own data only. When your assistant lists sequences, prospects, videos, tasks, or issues, the list contains your records and no one else’s — even when you share a team.
Your team’s data is included only when you ask for it. Four kinds of list can widen to the whole team, and only on request:
| Ask about | Assistant can widen to the team |
|---|---|
| Sequences | Yes |
| Prospects | Yes |
| Prospects’ progress in sequences | Yes |
| Issues affecting outreach | Yes |
| Videos | No — always yours only |
| Tasks | No — always yours only |
| Account totals and limits | No — always yours only |
“On request” means an explicit question about the team, such as “how many prospects is my team working right now”. A question about your numbers stays about your numbers.
There is one nuance worth naming. When your assistant opens a single record by its ID — one prospect, one sequence, one video — it can open that record if you own it or if it belongs to your team. This mirrors the Vaam web app, where you can already open a teammate’s prospect. It cannot open a record belonging to anyone outside your team, in any circumstance.
What it can change
Section titled “What it can change”Writing is a separate set of permissions from reading, and you see the full list before you approve. A connected assistant can:
- Pause and resume a sequence.
- Add prospects to a sequence, correct a prospect’s contact details, and remove a prospect.
- Pause, resume, or permanently stop outreach to one person.
- Mark an issue as resolved or dismissed.
- Create a video and finish uploading it.
- Change your AI outreach settings: your ideal customer profile, company details, offering, and message language.
One consequence to know about: if you are a team owner or team admin, changing the AI outreach settings also changes them for every member of your team. That is how those settings work in Vaam generally — the assistant is not doing anything special — but it is easy to forget when you are chatting rather than clicking.
An assistant never sends outreach itself. It starts and stops the work; Vaam performs it, on your normal schedule and within your normal limits.
Tools that only read are labelled as read-only, and tools that change data are labelled as writing, with a further flag on the ones that overwrite or remove something. Assistants show these labels, which is why Claude asks you to confirm a change but not a lookup.
What it can never reach
Section titled “What it can never reach”No matter what you approve, a connected assistant cannot:
- See data belonging to another team, or to a Vaam customer who is not you.
- See your password. You type it into Vaam’s own login page, in your own browser, never into the assistant.
- Reach billing, invoices, or payment details.
- Reach Vaam’s internal support and administration tools. Those live on a separate address, described below.
- Do anything after you disconnect it.
- Grant itself more than you approved. Permissions can be narrowed later but never widened, and they are checked against your live account rather than frozen at the moment you approved — so if your role in Vaam changes, the connection follows.
The permissions you approve
Section titled “The permissions you approve”The approval screen lists permissions in plain terms. This is what each one covers:
| On the approval screen | What it allows |
|---|---|
| Read sequences | See your sequences, their steps, and their stats |
| Write sequences | Pause and resume a sequence |
| Read prospects | See your prospects and their details |
| Write prospects | Add prospects to a sequence, correct their details, remove them |
| Read enrollments | See where each prospect is in a sequence |
| Write enrollments | Pause, resume, or stop outreach to one person |
| Read videos | See your video recordings and their view stats |
| Create videos | Upload a new video |
| Read stats | See your counts, totals, and account limits |
| Read work items | See issues affecting your outreach |
| Write work items | Mark an issue resolved or dismissed |
| Read user information | See your name, email, and account type |
| Read team information | See your team’s name, size, and connected integrations |
| Read settings | See your AI outreach settings |
| Write settings | Change your AI outreach settings |
Two of these lines use the word enrollments. It means a prospect’s progress through a sequence — the same thing the Vaam app shows you on a sequence page.
If you approve without the assistant asking for anything specific, you grant this whole list. An assistant that asks for a shorter list gets only what it asked for.
An API key carries the same permissions, except that you tick them yourself when you create the key. A key that only needs to read can be created with no write permissions at all. Permissions cannot be added to a key after the fact — you create a new key instead.
Ending access
Section titled “Ending access”You can end access at any time:
- Remove the connector in your assistant. See Disconnecting for where that is in each app. This deletes the tokens the assistant was holding, so it cannot sign in again.
- Delete the API key under Settings → API. The key stops working immediately.
- Email support@vaam.io if you cannot reach the assistant, or you think a connection has been misused. We can cut it off from our side.
Two details for a security review. A renewal token is single-use: it is replaced every time it is used, and if an old one is ever presented again, the whole connection is revoked immediately rather than given the benefit of the doubt. And an access token expires one hour after it is issued, which bounds how long a token that was already in flight can keep working after access ends.
Nothing in your Vaam account changes when access ends. Anything the assistant already did stays done — a paused sequence stays paused until you resume it. You can see what it did in your normal sequence and prospect history, because an action taken through an assistant is recorded the same way as an action taken in the Vaam app.
The administration address is separate
Section titled “The administration address is separate”Vaam runs a second MCP address for its own support staff, at a different URL. It is not part of this documentation and it is not available to customers.
It is genuinely separate, not the same address with a flag set. Access granted for the normal address is rejected at the administration address, and the reverse is also true. Approving a connection for your assistant cannot, by any route, produce access to internal tools.
Where your data goes
Section titled “Where your data goes”Vaam never sends your data to Claude, ChatGPT, or any other assistant on its own. It travels there because you connected the assistant, and only in answer to the question you asked — the same path it would take if you opened the Vaam app and copied the answer into a chat yourself.
Once it arrives, that data is handled by the assistant’s provider — Anthropic for Claude, OpenAI for ChatGPT — under their terms, not Vaam’s. Choose which assistants you connect with the same care you would apply to any other tool that reads your customer data, and check your provider’s data retention and training settings. See the AI assistants section of Vaam’s Privacy Policy for Vaam’s own position.
Vaam’s handling of your data is unchanged by connecting an assistant. See Personal Data Management, GDPR, and Sub-processors.
Getting help
Section titled “Getting help”Questions about a connected assistant, or about anything it did on your behalf: email support@vaam.io.
For Vaam’s full data handling commitments, see the Privacy Policy and the Terms of Service.
Related
Section titled “Related”- Connecting an AI assistant — walkthroughs, the approval screen, disconnecting.
- What your assistant can do — every tool, and what it does.
- Data Information Security Policy — Vaam’s wider security posture.