# Scopes and roles

What each scope allows, the role it needs, and the presets Studio offers.

A token (OAuth or personal) carries scopes. On every call Covo also checks the person's role on that Concierge: a scope never grants more than the role allows.

| Scope | Allows | Minimum role |
| --- | --- | --- |
| `agents:read` | See agents, their configuration, versions, drafts, deployment and diagnostics. | editor |
| `agents:write` | Change configuration, add knowledge, create drafts and versions. | editor |
| `agents:delete` | Remove links, offers, knowledge and Places as part of a change. Needs confirmation. | editor |
| `agents:test` | Run test conversations. Test replies count toward the AI reply allowance. | editor |
| `agents:publish` | Publish, unpublish and restore earlier versions of a live agent. Needs confirmation. | admin |
| `conversations:read` | Read conversations visitors had with an agent. These contain personal data. | editor |

## Presets

| Preset | Scopes | For |
| --- | --- | --- |
| `read_only` | `agents:read` | Inspect agents. Nothing can change. |
| `development` | `agents:read`, `agents:write`, `agents:test` | Inspect, change and test agents. Cannot publish or remove items. |
| `deployment` | `agents:read`, `agents:write`, `agents:test`, `agents:publish` | Everything in Development, plus publishing and rolling back. |

## Roles

- **Editor**: everything except publishing and rolling back.
- **Admin**: also publishes, unpublishes and restores versions.
- **Owner**: everything an admin can, plus billing and the team.

Read-only OAuth approvals keep only `agents:read` and `conversations:read` from what the app asked for.
