Permissions

Permissions

How SiteTrax.io decides what a person, and any assistant acting for them, is allowed to see.

The model

Everything resolves to one question: which projects are shared with this account. That single rule governs the application, the API and the MCP server. Connecting an assistant does not widen it, and no prompt can talk past it.

LayerWhat controls it
Application accessThe account sign-in
Which sites and yards are visibleProject sharing, managed on each project
What an assistant can reachThe projects shared with the account that authorized the connection
What an assistant is allowed to doThe OAuth scopes approved for that connection
Whose priorities shape a responseThe published Intelligence profile of that same account

Assistant scopes

Grant the write scope only where the workflow needs it. Integrations that expose SiteTrax.io through a read-only surface do not receive it.

Media

Images and video can be withheld independently of the record. Project configuration, retention, user permissions and redaction settings all affect availability, and a redacted record can return permitted operational metadata while withholding the media.

Profiles are personal

An Intelligence profile belongs to one user account. It is not an organization setting, it is not inherited, and one person answers do not shape another person results. Each person completes their own interview.

Administration in the current application is scoped to individual projects. This account did not expose an organization-wide roles console, so role-level administration is not documented here. If your organization uses one, contact SiteTrax.io so this page can be extended.


Revision #1
Created 2026-09-04 15:22:37 UTC by SiteTrax.io Admin
Updated 2026-09-04 15:22:38 UTC by SiteTrax.io Admin