DocsAI Assistant (MCP)What it can do & security

What it can do & security

What an AI assistant connected to Lead Distro AI can read and change, the permission model, rate limits, what it can never do (move money), and how to disconnect an assistant or revoke an API key.

Last updated:

Once connected, you ask the assistant in plain English and it uses tools scoped to your organization. What it can do depends on the permissions you granted.

What you can do

PermissionWhat the assistant can doExamples
Read & reportingLook up campaigns, buyers, suppliers, lead stats, and profit reports."How did the Solar campaign do last week?" "List my active campaigns."
Manage campaigns & fieldsCreate and update campaigns, edit field mappings and inbound filters, add and configure buyers and suppliers, and set up automations."Create a campaign called Auto Accident, add a required phone field, and add Acme as a buyer at $40."

Write actions run immediately when you ask for them. There is no separate approval step like the in-app assistant has, so review what you are asking for before you send it.

What it can never do

No matter how you connect, the assistant cannot move money. It cannot charge a buyer's card, refund a wallet, or send or void an invoice. Those billing actions are deliberately left out. An assistant also cannot do anything outside the one organization it is connected to.

Rate limits

Each connection is limited to 120 tool calls per minute, with a tighter cap of 30 write actions per minute. If you hit a limit, the assistant gets a clear message telling it how many seconds to wait, then it can continue. The limits are generous for normal use and exist to stop a runaway loop.

Disconnect or revoke access

Browser sign-in (Claude.ai, desktop, or Claude Code): go to Settings, then API Keys, and find the Connected AI assistants card. Click Revoke next to the assistant you want to disconnect. It loses access right away and would have to be authorized again.

API key: go to Settings, then API Keys, and click Revoke on any key. The key stops working within a minute. Revoke a key the moment a teammate leaves or you suspect it has leaked, then create a new one.

Frequently Asked Questions

Is it safe to let an AI assistant manage my account?
Every connection is scoped to one organization and only does what its permissions allow. Money movement (charging cards, wallet refunds, invoices) is never exposed at all. You can revoke any connection or key instantly, and only admins can create or revoke them. As with any credential, share keys carefully and revoke them if they leak.
What can the assistant not do?
It cannot charge a buyer's card, refund a wallet, or send or void an invoice. Those billing actions are deliberately left out of the connector. It also cannot do anything outside the organization it is connected to.
Which AI assistants can connect to Lead Distro AI?
Any client that supports the Model Context Protocol (MCP) over HTTP. For one-click browser sign-in, use Claude.ai, the Claude desktop app, or Claude Code. For Cursor, Windsurf, and other JSON-config clients, add the endpoint https://mcp.leaddistro.ai/mcp and pass an API key as a bearer token. Headless setups like scripts and scheduled jobs also use an API key.
How do I disconnect an assistant?
For browser sign-in, go to Settings, then API Keys, and click Revoke under Connected AI assistants. For an API key, click Revoke on the key. Either one cuts off access.

If you have any questions, send us an email at support@leaddistro.ai