Skip to content
Covo Developers

Concepts

Scopes and roles

What each scope allows, the role it needs, and the presets Studio offers.

A token (OAuth or personal) carries scopes. On every call Covo also checks the person's role on that Concierge: a scope never grants more than the role allows.

ScopeAllowsMinimum role
agents:readSee agents, their configuration, versions, drafts, deployment and diagnostics.editor
agents:writeChange configuration, add knowledge, create drafts and versions.editor
agents:deleteRemove links, offers, knowledge and Places as part of a change. Needs confirmation.editor
agents:testRun test conversations. Test replies count toward the AI reply allowance.editor
agents:publishPublish, unpublish and restore earlier versions of a live agent. Needs confirmation.admin
conversations:readRead conversations visitors had with an agent. These contain personal data.editor

Presets

PresetScopesFor
read_onlyagents:readInspect agents. Nothing can change.
developmentagents:read, agents:write, agents:testInspect, change and test agents. Cannot publish or remove items.
deploymentagents:read, agents:write, agents:test, agents:publishEverything in Development, plus publishing and rolling back.

Roles

  • Editor: everything except publishing and rolling back.
  • Admin: also publishes, unpublishes and restores versions.
  • Owner: everything an admin can, plus billing and the team.

Read-only OAuth approvals keep only agents:read and conversations:read from what the app asked for.