Projects, roles and API keys
One project per brand. Keys give a project to your own tools; roles decide what a key or a member may do.
Projects
A project is one brand: its connected accounts, posts, calendar, knowledge, voice and workflows. Make one per brand or client from the project switcher in the top bar. Credits are yours, not the project's, and are shared across all of them; the ledger records which project spent what.
Roles
| Role | Can |
|---|---|
| Viewer | Read everything: posts, calendar, knowledge, profile |
| Editor | Write, edit, schedule, make pictures |
| Admin and owner | Everything, including publishing, disconnecting accounts and deleting |
The same rules hold in the chat, over MCP and over REST: a viewer's API key cannot publish any more than a viewer can.
API keys
Under Settings → API & MCP, make a key for the project. It can do in that project everything you can, and nothing in your other projects. The key is shown once; keep it like a password, and revoke it there if it leaks. Every call made with it is in the activity log.