Access, publish limits and what gets filtered
The three levels of access, how the publish limit works, and why your assistant sees fewer tools than exist.
The three levels of access
| Access | What it allows |
|---|---|
| Read | Read your Koast data. |
| Write | Change your Koast data. Drafts, settings, live edits. |
| Publish | Push campaigns live to the ad platform. |
They stack. A connection with Read and Write can build a whole campaign and still cannot put it live.
The publish limit
Publish is the only access that spends money, so it carries its own cap. The publish limit is the most one connection may ever put live, in total, across its whole life. It is not a daily budget and it is separate from your ad account budgets.
Without a limit, publishing is refused. The publishing tools don't appear at all until you set one, so an assistant can draft an entire launch and still have no way to push it.
Why your assistant sees fewer tools than exist
The list is filtered on every request, by four things:
- The access you granted. Read only hides every write and publish tool.
- Your role on the team. The connection can never do more than you can.
- Your plan. Tools your plan doesn't include are not offered.
- The active brand's ad provider. Meta and Koast ad accounts support different things.
A read only connection sees 33 tools. Read, Write and Publish on a Meta brand sees 71.
Filtering happens in the server, not in the prompt
The server refuses a call for a tool that isn't on the list, and names the access that would have carried it. That boundary doesn't depend on the assistant behaving well.
Revoking
Revoke a key or an authorized app from API Keys in Settings. It takes effect on the connection's next request, not at the end of its session.