What an AI Assistant Can and Can't Change
An AI assistant connected through MCP can change things in By the Numbers only when its connection allows changes. Those changes are then limited by your own permissions on the team.
How It Works
Whether a connection can make changes depends on how it was set up:
- A token can only read, unless you ticked Allow changes, not just reads when you created it.
- A sign-in gets only the access you tick, out of what the AI app asks for. Read starts ticked and Write starts unticked, so a sign-in can make changes only if you tick Write.
The Access column on the MCP page shows Read Only or Read & Write for each one.
Permissions an Assistant Still Needs
Changes are checked against your own permissions on the team, the same as in the app:
- Creating a shared dashboard, or sharing a personal one, needs Edit dashboards. So does changing a shared dashboard’s cards, name, icon, Free Positioning or default filters, sharing a saved view, or deleting a shared dashboard. An assistant can create a personal dashboard, and change one you created, without it.
- Connecting, changing or disconnecting integrations, changing where segments sync, syncing a segment now, changing das Pixel’s capture settings, and switching a platform’s server-side conversions on or off, need Manage integrations.
- Exporting a report or a segment needs Export data.
- Inviting, changing or removing team members needs you to be an owner of the store.
What an Assistant Can Change
With Read & Write access, an assistant can:
- Create, edit, copy and delete customer segments, and refresh a segment’s summary
- Sync a segment to a connected platform, change its sync, sync it now, or stop syncing it
- Email a link to a segment’s customers as a CSV file, to your own email address only
- Create, edit, copy and delete dashboards and saved views, and pin, move, resize and remove cards
- Create, edit and delete annotations, forecasts and goals
- Connect Klaviyo with its private API key, change an integration’s settings, or disconnect one
- Change das Pixel’s capture settings, and switch server-side conversions on or off for each ad platform
- Invite team members, change their role and permissions, or remove them
- Update your own profile, your store’s preferences and business profile, and your loyalty group thresholds
- Snooze a setup task for 7 days
Disconnecting an integration also removes the segment syncs that send to it, and turns off scheduled exports that deliver to it. It also tries to revoke By the Numbers’ access in the other platform’s account, the same as disconnecting in the app. This covers Google Ads, Google Analytics, Meta, TikTok and Klaviyo.
For Google, the access is kept while another Google integration is still connected. Google Drive access is never revoked. To remove either, use your Google account’s third-party access settings.
What an Assistant Can’t Change
- Your plan, billing or add-ons
- Connecting an integration that needs you to sign in to the other platform, such as Google Ads, Meta, TikTok or Google Analytics
- Whether das Pixel is connected, or where conversions are sent
- Anything in Shopify: products, orders, customers, discounts and your store’s settings stay as they are
- Another store’s data, even one you belong to
- Your teammates’ MCP connections and tokens
Do those in the app, or in Shopify.
What It Means for You
- Give an assistant Read & Write access only when you want it to make changes. Read-only covers questions about your data. For a sign-in, leave Write unticked to get read-only.
- An assistant acts as you. The Audit Log records its changes with AI Assistant (MCP) as the source, for the areas it covers.
- An assistant can misread a request. Ask it what it will delete or remove before it does, since deleted segments, dashboards and goals can’t be restored.
- An assistant sends a segment export only to your own email address. Forward it if someone else needs the file.
- When a team member leaves or is removed, their tokens and sign-ins stop working at once.