01
Identity and authorization
- Human session for the portal and OAuth 2.1 with PKCE consent for compatible connectors.
- Permissions are separate: read queries data, write prepares changes, and approve lets a person decide on the exact proposal.
- Only the account owner or an administrator can authorize approvals; existing connections must be authorized again before their permissions expand.
- dpk_ and dpa_ are revocable advanced options but can never approve.
