Skip to main content
When someone links an account, they only see the connector profiles they’re allowed to link through. Each profile is either Shared or Restricted: Project Admins can still view, edit and delete a restricted profile.

When to restrict a connector profile

Restrict a profile when its configuration is sensitive and only some people should connect through it. Each of them still links their own account.
A user can reach a provider by linking their own account through a connector profile, or by using an account someone else has already linked:
Example cases:
A sales team of account executives, with two sales managers who also fix records in bulk.
  1. Create two CRM connector profiles: one with admin scopes, and one with read-only scopes.
  2. Restrict the admin-scoped profile, and leave the read-only one Shared.
  3. Grant the sales managers Connector Profile Member on the admin-scoped profile.
  4. Each manager links their own CRM account through the admin-scoped profile.
  5. Everyone else links through the read-only profile.
An HR team that handles payroll.
  1. Restrict the HR connector profile that reaches payroll data.
  2. Grant the HR team’s group Connector Profile Member on it.
  3. Only the HR team can link accounts through it.

Access to a restricted connector profile

A grant gives a user or group one of two roles, Connector Profile Admin or Connector Profile Member. On a restricted connector profile:
Connector profile access shown for three users in Project 1. User A is a Project Admin, User B a Project Member granted Connector Profile Member on the restricted profile, and User C a Project Member with no grant. On the shared profile, User A manages it and Users B and C can link accounts through it. On the restricted profile, User A can edit it but not link accounts through it, User B can link accounts through it, and User C has no access.

Restrict a connector profile

Restricting a shared profile needs Project Admin or Organization Admin. Once it’s restricted, only a Connector Profile Admin can change its access.
1

Open the profile's Access tab

  1. Go to Connector Profiles and open the profile.
  2. Select its Access tab.
2

Switch it to Restricted

Change the selector from Shared to Restricted. You become its Connector Profile Admin automatically, so you can’t lock yourself out.
Accounts already linked through the profile stay linked, and can still be re-authenticated through it without a grant.
3

Grant users and groups

  1. On the Members view, click Add member for each person.
  2. On the Groups view, click Add group for each group.
  3. Choose Connector Profile Admin or Connector Profile Member for each.
A connector profile's Access tab set to Restricted, warning that only the listed members and groups can link new accounts while already-linked accounts stay connected, above a member roster with Admin and Member roles
A group’s grant covers everyone in it, and follows the group as people join or leave. See Groups. To change access later, a Connector Profile Admin edits the same Access tab. A restricted profile must keep at least one Connector Profile Admin, so hand the role to someone else in the same save, or switch the profile back to Shared.

The default for new connector profiles

Each project has a Default Access setting that decides whether connector profiles created from then on start Shared or Restricted. Only an Organization Admin can change the default:
  1. Go to Project Settings > Connector Profiles.
  2. Under Default Access, choose Shared or Restricted.
  3. Click Save.

Scoping Connectors

Choose which of a profile’s actions and events are exposed.

Groups

Grant many users the same access at once with reusable groups.

Linking Accounts

Connect the provider accounts your agents act on.

Manage Team

Add people to the organization, and remove their access when they leave.