Authentication
What API keys and connected apps can see
On this page
Bizisy treats every API key and every connected AI app as a machine. A machine acts as its person, with their role, but it gets less than that person does in the web app: other people's private and pay data never leave Bizisy through a machine, and a few actions stay with a person signed in to Bizisy.
These rules are checked by the server on every call, the same way for REST and MCP and for keys and connected apps. They don't depend on the client.
Other people's private and pay data#
Each field of a person has a visibility tier: public, job, private or pay.
| Tier | A person in the web app | A machine |
|---|---|---|
| Public (name, work email, title, team, photo) | Everyone in the company | The same |
| Job (job details and history, contract terms) | The person, their managers, owners, admins and HR | The same |
| Private (personal contact details, address, birthday, emergency contacts, payroll identifiers) | The person, owners, admins and HR | Only the person's own |
| Pay | The person, owners, admins and HR | Only the person's own |
So an HR Manage key reading someone else gets their public and job tiers: private fields come back null and private custom fields are left out (visible_tiers says which tiers you got). The same key reading its own person gets everything. Webhook payloads follow the same rule.
Files follow it too: through a machine, other people's documents come as metadata only and never download, and someone else's file in a custom field shows its size and type, not its name.
Actions that stay in the web app#
Some actions are refused for every machine, whatever the role. They hand out secrets, move money or switch off a safeguard, so a person signed in to Bizisy does them:
| Action | Why |
|---|---|
platform.billing.checkout | Payment pages open in the browser, for owners and admins signed in to Bizisy. |
platform.billing.portal | Payment pages open in the browser, for owners and admins signed in to Bizisy. |
platform.billing.invoices.pdf | Invoices download in the browser, for owners and admins signed in to Bizisy. |
platform.billing.pay | Invoices are paid on Stripe's page in the browser, by owners and admins signed in to Bizisy. |
org.pay.add | Pay is recorded in the app only. |
org.pay.remove | Pay is changed in the app only. |
org.approvals.settings.update | Who approves changes is set in the app only, so an assistant can never switch approval off. |
org.approvals.approve | Approving needs a person signed in to Bizisy. |
org.approvals.reject | Rejecting needs a person signed in to Bizisy. |
webhooks.endpoints.create | Endpoints are added in the app only (the result is a secret, and data starts flowing to a new place). |
webhooks.endpoints.delete | Endpoints are deleted in the app only. |
webhooks.endpoints.roll_secret | Secrets are rolled in the app only (the result is a secret). |
The API reference marks them Web app only.
Actions with limits for machines#
These work for machines, with a limit:
| Action | For keys and apps |
|---|---|
platform.connections.revoke | Only your own connections (owners and admins disconnect others in the app). |
org.people.list | The HR filters legal_entity_id, joined_between and left_between are refused. |
org.people.get | Private fields only for yourself. |
org.people.update_profile | Payroll details (tax_id, social_security_number, iban) are refused. |
org.me.update | Payroll details (tax_id, social_security_number, iban) are refused. |
org.setup.apply | Payroll details are refused. |
org.people.import_csv | Payroll details and private custom fields are refused. |
org.invites.create | url is null: the sign-in link is only emailed to the person. |
org.fields.update | confirm_expose_existing (widening a tier while people have values) is refused. |
org.pay.list | Only your own pay. |
org.people.export_csv | include_private is refused. |
org.people.export_data | Only for yourself (or use org.me.export_data). |
org.positions.list | pay_range (the budget) is never returned (pay_range_hidden is true). |
org.positions.create | pay_range is refused. |
org.positions.update | pay_range is refused. |
documents.list | Other people's documents come as metadata only. |
documents.download | Other people's documents never download. |
documents.field_file.start | Other people's files are never returned. |
webhooks.endpoints.update | Only turning an endpoint off, its description and removing event types; a new URL, more events or turning it on happen in the app. |
Why#
- AI assistants act for people, they don't replace them. An assistant can prepare a change and preview it, but approving a change, recording pay or switching approvals off needs the person.
- A leaked key is bounded. A key that leaves your servers can't read anyone's bank details or home address, can't add a webhook that sends data somewhere new, and can't create more keys.
- Exports of private data happen in the app, where the person sees what they download.
Machines in Activity#
Everything a machine changes shows in Activity with the key's or the app's name. Through MCP, previews (dry runs) and failed attempts are recorded too, so you can see what an assistant tried, not only what it did.
Something missing or wrong on this page? Write to hello@bizisy.com.