Permissions Reference

Every permission an assistant or API key can hold, what it unlocks, and which ones can change records — generated from the server.

Every capability on the API and the MCP server is gated by a permission (a "scope"). You tick permissions on the consent screen when connecting an assistant, or when creating an API key. A permission marked "writes" can change records; leave those unticked for a strictly read-only connection.

Not every permission fits every kind of account — a tenant cannot be granted owner statements, a contractor cannot be granted the power to publish a landlord's listing. The consent screen and the key editor only offer what your account type can hold, and the server refuses the rest even if asked directly.

Account

PermissionNameWritesWhat it allows
account:readAccount profilenoRead the connected account's name, role and plan.
team:readTeamnoRead staff, technicians and their property assignments, and how far from the job site a shift was clocked in.
offers:readRewards & referralsnoRead the account's referral link, earned rewards and Seayora credit balance.
billing:readSubscriptionnoRead the Seayora plan, invoices and billing status.

Leasing

PermissionNameWritesWhat it allows
listings:readRental marketplacenoSearch apartments listed on Seayora, anywhere — not just yours.
listings:writePublish listingsyesPost a new rental listing publicly on Seayora on this account's behalf.
applications:readApplicationsnoRead rental applications and screening status.
applications:writeDecide applicationsyesPre-approve, accept or reject rental applications.
marketing:readListing performancenoRead listing views, marketing reach and which partner feeds a listing is syndicated to.
showings:readTours & showingsnoRead tour availability and booked showings.
showings:writeBook & manage toursyesBook a tour on a listing, cancel one, or record how a showing went.
renewals:readRenewals & noticesnoRead expiring leases, renewal offers, and the notices served on a tenancy.
evictions:readEviction casesnoRead eviction cases on this account — what stage each is at, the steps the state and city require, and the record. Read-only: nothing on this surface can start, advance or file one.

Portfolio

PermissionNameWritesWhat it allows
properties:readPropertiesnoRead units, addresses, rent and amenities.
properties:writeEdit propertiesyesChange rent, availability, description and policies.
tenants:readTenantsnoRead tenant names and contact details.
leases:readLeasesnoRead lease terms, status and signatures.

Money

PermissionNameWritesWhat it allows
payments:readRent paymentsnoRead the rent roll, arrears and payment history.
payments:writeAsk to spread a rent chargeyesAsk this account’s landlord for a payment plan on rent it cannot pay in full. It only ASKS — it can never approve, sign or pay anything.
accounting:readAccountingnoRead invoices, bills, expenses, vendors and the chart of accounts.
owners:readOwner statementsnoRead owners, distributions and the owner ledger.
deposits:readSecurity depositsnoRead deposits held, deductions, return deadlines and the statute behind them.
analytics:readPortfolio analyticsnoRead occupancy, rent roll, arrears, delinquency reports and building health scores.

Operations

PermissionNameWritesWhat it allows
maintenance:readWork ordersnoRead maintenance jobs and their status.
maintenance:writeManage work ordersyesOpen, reschedule, reassign and close maintenance jobs.
tasks:readTasksnoRead property-management tasks.
tasks:writeManage tasksyesCreate, update and complete tasks.
calendar:readCalendarnoRead scheduled showings, inspections and meetings.
calendar:writeSchedule eventsyesCreate calendar events and showings.
inspections:readInspectionsnoRead move-in, move-out and periodic inspection reports and their findings.
compliance:readCompliancenoRead Local Law 97 carbon caps, city violations and enforcement, and housing-program filings and deadlines.
safety:readYour insurance, licences & safety recordnoFor a contracting business: which certificates it is required to hold and whether they are in date, and which vendors it owes a 1099.
iot:readConnected devicesnoRead meters, sensors and thermostats — live values, usage history and the alerts they raised.

Communication

PermissionNameWritesWhat it allows
messages:readMessagesnoRead message threads with tenants, owners and pros.
messages:writeSend messagesyesSend messages on the account's behalf.
community:readResident communitynoRead building announcements, package deliveries and amenity bookings.
community:writePost to the buildingyesPost an announcement to every resident, or log a delivered package. Operator-side.
amenities:writeBook an amenityyesReserve a shared space — roof deck, laundry, party room — as a resident.

Documents

PermissionNameWritesWhat it allows
documents:readDocumentsnoRead document metadata — titles, types and tax years.

How permissions are enforced

  • On the server, on every single call — not in the assistant. A tool the credential does not hold the permission for is not merely hidden; calling it directly is refused.
  • A connection can only ever narrow what it was granted. Refreshing its credential cannot widen it.
  • The ceiling is your account type. Approving a proposal re-checks it against your own permissions, so an assistant can never do through you what you could not do yourself.

Related guides

Related features and guides

  • Connecting an AI Assistant to Seayora — Documentation. What it means to connect Claude, ChatGPT or your own software to your Seayora account, what an assistant can and cannot do, and the one URL you need.
  • API Authentication & API Keys — Documentation. The three credentials Seayora accepts, live versus test keys, what a credential can see, and how to keep keys safe.
  • MCP Server Reference — Documentation. Transport, protocol versions, and the full generated catalogue of tools, resources and prompts the Seayora MCP server offers.
  • Audit Logs — Feature. Audit logging across consequential actions, so account activity, permission changes, and financial entries all leave a reviewable trail.

Explore Seayora