Is connecting an AI assistant to Decisa safe?

1 min readLast verified 2026-06-17

Yes — and it's designed so you stay in control. There's no secret key to leak, the assistant only ever gets your permissions, money-moving changes need your approval, and you can cut access off in one click.

Why it's safe by design

No API key to copy or leak. You connect by signing in to Decisa in your browser, the same way you log in normally. No secret token is ever pasted into the assistant, so there's nothing to accidentally share or have stolen.

It only gets your permissions. A connected assistant inherits your role in each workspace. It can't see or do anything you can't — if you have no access to billing, neither does it.

Money-moving changes need your approval. Anything that spends or risks money — budgets, pausing or launching campaigns — becomes a draft you review and apply. The assistant proposes; you decide. See Review and apply changes.

You can cut it off instantly. Revoke a connection and it loses access immediately, everywhere. Block a single workspace and it loses access just there. See Manage and revoke AI access.

Choose how much it can do: read-only vs full access

When an assistant connects, it asks for one of two levels — shown on each connected app as a label:

  • Read-only — it can look at data and pull reports, but cannot create, edit, pause, spend, or change anything. Best when you only want answers.
  • Full access — it can also draft changes for your review. It still can't apply money-moving changes without your approval.

If you're not sure, start read-only. You can always reconnect with full access later.

The extra guardrail for changes

Because one connection spans all your workspaces, an assistant must name the exact workspace before it changes anything there. If it tries to make a change without naming the right workspace, Decisa refuses and asks it to confirm first — so a change can't land in the wrong workspace by mistake.

What's recorded

Decisa keeps an audit trail of meaningful actions, so changes made through an assistant are traceable just like changes made by hand. Your sign-in is the one approval the assistant needs — Decisa never logs or exposes your password or any secret key.

Want to double-check what a given assistant can reach right now? Open Settings → AI Access (MCP) — "Connected apps" shows each one's access level, and "What an AI client can do here" lists the available tools for the workspace you're viewing.

One thing to remember: a connection stays live until it expires or you revoke it — closing the chat or deleting the app on your computer does not end Decisa access. If a device is lost or you're done with a tool, revoke it.