SECURITY

Workspace boundaries and reviewable operations.

Bizcraw is designed around separated workspaces, explicit access checks and controlled connections to external providers.

Last updated: October 8, 2026
01

Workspace isolation

Business records are associated with a workspace, and application workflows resolve the active workspace before reading or changing customer data.

  • Workspace-scoped database access
  • Role and membership checks
  • Plan and module permission enforcement
02

Credentials and integrations

Provider credentials are handled through server-side workflows. Users should never place API keys in notes, prompts, imported files or other general workspace fields.

03

AI and sensitive actions

AI access follows the current workspace and user permissions. Supported high-impact operations can require an approval step and create operational records for later review.

  • Permission-aware context
  • Approval gates for sensitive operations
  • Audit-oriented operational history
04

MCP connections

MCP connections use scoped access, expiring credentials and workspace checks. OAuth access tokens are bound to the Bizcraw MCP resource, and connections can be revoked by workspace administrators.

  • Minimum read scopes by default
  • Write tools controlled separately from read tools
  • Audit records for tool calls and approval-gated actions
05

Report a concern

If you believe you found a security issue, contact the Bizcraw team with a clear description, affected URL and reproduction steps. Do not access or alter data that does not belong to you.

NEXT STEP

Need help with a workspace or policy question?

Open the contact page for the latest support, privacy and security request information.

Contact Bizcraw