Concepts
Scopes and roles
What each scope allows, the role it needs, and the presets Studio offers.
A token (OAuth or personal) carries scopes. On every call Covo also checks the person's role on that Concierge: a scope never grants more than the role allows.
| Scope | Allows | Minimum role |
|---|---|---|
agents:read | See agents, their configuration, versions, drafts, deployment and diagnostics. | editor |
agents:write | Change configuration, add knowledge, create drafts and versions. | editor |
agents:delete | Remove links, offers, knowledge and Places as part of a change. Needs confirmation. | editor |
agents:test | Run test conversations. Test replies count toward the AI reply allowance. | editor |
agents:publish | Publish, unpublish and restore earlier versions of a live agent. Needs confirmation. | admin |
conversations:read | Read conversations visitors had with an agent. These contain personal data. | editor |
Presets
| Preset | Scopes | For |
|---|---|---|
read_only | agents:read | Inspect agents. Nothing can change. |
development | agents:read, agents:write, agents:test | Inspect, change and test agents. Cannot publish or remove items. |
deployment | agents:read, agents:write, agents:test, agents:publish | Everything in Development, plus publishing and rolling back. |
Roles
- Editor: everything except publishing and rolling back.
- Admin: also publishes, unpublishes and restores versions.
- Owner: everything an admin can, plus billing and the team.
Read-only OAuth approvals keep only agents:read and conversations:read from what the app asked for.