What it can do & security
Everything an AI assistant connected to Lead Distro AI can read and change, grouped by area, plus the permission model, rate limits, what it can never do (move money), and how to disconnect an assistant or revoke an API key.
Once connected, you ask the assistant in plain English and it uses tools scoped to your organization. What it can do depends on the permissions you granted.
Permission levels
Permissions are set per area, each as None, Read, or Write, the way a restricted key works on a payments dashboard. A new API key starts read only, which is enough for reporting; turn on Write only for the areas the assistant must change. The same permissions apply whether the assistant connects over MCP or a script calls the Actions API.
| Area | Read lets it | Write lets it |
|---|---|---|
| Campaigns | List and inspect campaigns, their fields, filters, and post specs | Create campaigns, change settings, edit fields and filters, set up ping-post |
| Destinations | List buyers and inspect their delivery and ping setup | Create buyers, attach them to campaigns, set delivery, ping, transforms, and call targets |
| Sources | List suppliers | Create suppliers, attach them to campaigns, set cost modes |
| Leads | Open leads and their routing trail (contact details hidden unless you ask) | Post outcomes back, add notes, send $0 test leads and pings |
| Funnels | List funnels and templates | Create, edit, and publish funnels, run A/B tests |
| Reports | Pull lead stats, breakdowns, and campaign performance | No write level |
| Partner Portal | See who has portal access | Turn on the portal, add members, set portal rules |
| Automations | No read level | Create automations on lead events |
| Integrations | List ad accounts and ad campaigns | Map an ad campaign to a source for spend tracking |
Write actions run immediately when you ask for them. There is no separate approval step like the in-app assistant has, so review what you are asking for before you send it.
What you can do
Everything the assistant can do, grouped by area. The Needs column is the permission each capability requires: the area plus Read or Write.
| Area | You can ask it to | Needs | Example |
|---|---|---|---|
| Reports & insights | List and inspect campaigns, buyers, and suppliers | Campaigns, Destinations, Sources: Read | "List my active campaigns." |
| Reports & insights | Pull lead counts, revenue, cost, and profit for any date range | Reports: Read | "What was my profit last week?" |
| Reports & insights | Break leads down by campaign, buyer, supplier, status, or state | Reports: Read | "Break down last month's leads by state." |
| Reports & insights | Review a campaign's full P&L with per-buyer and per-supplier detail | Reports: Read | "How is Auto Accident doing, by buyer?" |
| Reports & insights | List or open individual leads (contact details stay hidden unless you ask) | Leads: Read | "Show me yesterday's rejected leads." |
| Reports & insights | Explain why a lead was routed the way it was | Leads: Read | "Why did this lead go to Acme?" |
| Reports & insights | Check setup progress, or get the post instructions a supplier needs | Campaigns: Read | "Give Acme the post spec for Solar." |
| Campaigns & fields | Create a campaign or change its settings | Campaigns: Write | "Create a campaign called Auto Accident." |
| Campaigns & fields | Add lead fields, or rewrite the whole field list | Campaigns: Write | "Add a required phone field." |
| Campaigns & fields | Set inbound filters that accept or reject incoming leads | Campaigns: Write | "Reject leads from outside California." |
| Campaigns & fields | Turn a campaign into a ping-post exchange | Campaigns: Write | "Make Solar ping-post with a 20% margin." |
| Destinations | Create a buyer or update its details | Destinations: Write | "Add a buyer called Acme." |
| Destinations | Add a buyer to a campaign with price, priority, caps, and state filters | Destinations: Write | "Add Acme to Solar at $40, 50 a day, CA only." |
| Destinations | Set delivery (webhook, email, Google Sheets, SMS, GoHighLevel) and which fields to send | Destinations: Write | "Deliver to Acme by webhook with name and phone." |
| Destinations | Pause, activate, or change pricing, caps, and billing model (per lead or per conversion) | Destinations: Write | "Switch Acme to pay only on conversion." |
| Destinations | Configure a buyer's real-time bid (ping) in a ping-post campaign | Destinations: Write | "Set Acme's ping endpoint and bid field." |
| Sources | Create a supplier or update its details | Sources: Write | "Add a supplier called FB Ads." |
| Sources | Add a supplier to a campaign with a cost per lead and caps | Sources: Write | "Add FB Ads to Solar at $12 per lead." |
| Sources | Set how cost is calculated (flat, variable, ad-account spend, or revenue share) | Sources: Write | "Pay FB Ads 30% of each lead's revenue." |
| Sources | Pause, resume, or re-cap intake from a supplier | Sources: Write | "Cap FB Ads at 200 leads a day." |
| Automations | Set up a rule on lead events that sends a webhook, email, Slack, or Google Sheets row | Automations: Write | "Slack me when a lead is accepted." |
| Partner Portal | Turn on the Partner Portal for a buyer | Partner Portal: Write | "Enable the portal for Acme." |
| Partner Portal | Add or invite portal members, or see who already has access | Partner Portal: Write | "Invite ops@acme.com to Acme's portal." |
| Partner Portal | Set the portal's return policy | Partner Portal: Write | "Let Acme request returns within 7 days." |
| Testing & outcomes | Send a $0 test lead to confirm routing and delivery work | Leads: Write | "Send a test lead through Solar." |
| Testing & outcomes | Run a $0 ping-post dry run to see every buyer's bid | Leads: Write | "Test the ping-post exchange on Solar." |
| Testing & outcomes | Post a buyer's conversion back, or mark a delivered lead not qualified | Leads: Write | "Mark lead |
| LeadProsper import | Preview what would be migrated, changing nothing | Campaigns: Read | "Preview a LeadProsper import." |
| LeadProsper import | Run the import after you review the plan (buyers arrive paused) | Campaigns: Write | "Go ahead and import it." |
What it can never do
No matter how you connect, the assistant cannot move money. It cannot charge a buyer's card, refund a wallet, or send or void an invoice. Those billing actions are deliberately left out. An assistant also cannot do anything outside the one organization it is connected to.
Rate limits
Each connection is limited to 120 tool calls per minute, with a tighter cap of 30 write actions per minute. If you hit a limit, the assistant gets a clear message telling it how many seconds to wait, then it can continue. The limits are generous for normal use and exist to stop a runaway loop.
Disconnect or revoke access
Browser sign-in (Claude.ai, desktop, or Claude Code): go to Settings, then API Keys, and find the Connected AI assistants card. Click Revoke next to the assistant you want to disconnect. It loses access right away and would have to be authorized again.
API key: go to Settings, then API Keys, and click Revoke on any key. The key stops working within a minute. Revoke a key the moment a teammate leaves or you suspect it has leaked, then create a new one.
Frequently Asked Questions
Is it safe to let an AI assistant manage my account?
What can the assistant not do?
Which AI assistants can connect to Lead Distro AI?
How do I disconnect an assistant?
Related Articles
If you have any questions, send us an email at support@leaddistro.ai