# AI Access and data security

## Access and isolation

Alunta AI Access uses MCP and OAuth. The user selects a specific team during authorization and should check the account name before approving the connection. A connection applies to the selected account.

Only a user allowed to manage AI Access can create or retain the connection. Access ends if the token expires or is revoked, the authorization is revoked, the user loses that permission, or AI Access is disabled for the team.

## Read-only access

The team's MCP tools are read-only. They can analyze and return data, but they cannot create, change, send, or delete customers, subscriptions, invoices, payments, or configuration.

Aggregate business metrics and app states are available while AI Access is active. Details about specific invoices and end customers are separate data categories that an administrator can enable or disable. Plan names, pricing models, configured prices, checkout visibility, and payment-provider restrictions are a third separate category. The current tool list reflects these choices.

When Customer details are enabled, a team administrator can separately approve individual team-wide customer custom fields. Only approved fields can be listed, returned, or used as filters. New fields are not shared automatically, and plan-level subscription fields are never included through this setting. Custom-field names and values are treated as data, never as instructions.

## Product knowledge is not team data

Product knowledge consists of selected product guides, changelog entries, the public integration guide, and the public OpenAPI contract. The tool cannot select arbitrary files or use a team's private documents as product knowledge.

Documentation describes general capabilities. It does not prove that an app is enabled or correctly configured for the selected team. Use team status tools for that assessment.

## Revocation and privacy

An administrator can view active AI connections and revoke them in Alunta settings. Revocation prevents further use of that connection. Data already sent to an external AI client is then governed by that client's own processing and retention terms.

## Safe use

Never send access tokens, passwords, private keys, or other secrets in a question. Store secrets in a password manager, environment variable, or other approved secret manager.

## Bookkeeping access

Payment details require a separate opt-in that is disabled by default. Invoice and payment lookups also require invoice-detail and customer-detail permissions. Data status and payment setup can be shown with only the payment flag, without customer data, amounts or document counts. Re-enabling the module does not automatically re-enable payment-detail sharing.

An owner or administrator can give an existing team member individual, revocable bookkeeping access. The member receives the nine read-only bookkeeping tools plus definitions, team context and product knowledge. This does not grant an administrator role or permission to change bookkeeping, integrations or AI settings. The connection profile is fixed: later administrator rights do not automatically upgrade an already approved bookkeeping token.

Membership, bookkeeping grants and module availability are checked on subsequent requests. A saved report or previously discovered tool list is not an independent permission. Sharing totals on a common accounting ledger requires separate grants; a shared agreement number is insufficient. An aggregate may still disclose sensitive financial information even when document details are hidden.
