Where: Home → Connect your AI tools → Your tools → Permissions.
What a link can do#
A link works in one workspace, with the permissions you set for that tool. It can't see your other workspaces.
| What the AI tool can do | |
|---|---|
| Every link | Read your accounts, posts, calendar, Media Library, brand kit, business facts and analytics, for the accounts it may use. Save, edit and delete drafts. Send drafts for approval. Add photos and videos. Make Hero_Photo images (they use photo credits). Change your brand voice, brand kit, business facts and Hero_Photo subjects. |
| With Publish and schedule (on for new links) | Schedule posts, publish them now, and edit, reschedule or delete posts that are scheduled, published or waiting for approval. |
| With Read the inbox (owner on Growth or higher) | Read comments, messages and mentions, and mark them read, done or bookmarked. |
| With Reply in the inbox (owner on Pro or Agency; off for new links) | Reply to comments and messages as your account. |
| Which accounts | Limits all of the above to the accounts you pick. |
Heropost checks these on every call, not only when the tool connects. Changes apply straight away.
What stays in the app#
An AI tool can't reach any of these, whatever its permissions:
- Billing, plans and payment details
- Your password, email and sign-in
- Team members, roles and invitations
- Workspace settings, and your other workspaces
- Connecting, reconnecting or removing social accounts
- Making, replacing or removing AI-tool links
- Post Groups, automations and MonoL.ink
- Your Hero_Agent conversations
Deleting a post from an AI tool removes it from Heropost only. A post that's already published stays on the network.
The link is the key#
- Anyone who has the link can use it, with its permissions, in this workspace. There's no second sign-in. As Heropost puts it: "Anyone with a link can act on this workspace. Remove a tool to stop it instantly."
- It's shown once. Heropost doesn't show it again.
- New link replaces it. The old link stops working at once; the permissions stay.
- Remove cuts the tool off at once.
- It expires after 180 days without use.
Keep it secret:
- Don't paste it into shared documents, tickets, group chats or code you share.
- Don't show it in screenshots or screen shares. In anything you send, mask it like this:
hp_ag_xxxx…. Don't send the full link to anyone, including support. - Where your tool supports it, send the key in a header instead of inside the link. It stays out of address bars, shell history and screen shares. See Keep the key out of the URL.
- Give each tool, and each person, its own link. Then Activity shows who did what, and you can remove one without affecting the others.
Set it up safely#
- Decide whether it may publish. Publish and schedule is on for new links. Switch it off until you trust the tool, and everything it writes waits as a draft.
- Pick the accounts. Under Which accounts, choose Only the ones I pick and tick the ones it needs.
- Leave Reply in the inbox off unless you want it answering people in public, in your name.
- Use approvals for a second pair of eyes. If your workspace requires approval, AI tools can't schedule or publish a post until a reviewer approves it in Team → My Approvals. See Approvals.
- Keep tool approval on in your AI tool, so it asks before acting (below).
- Look at Activity now and then. Every post saved, scheduled or published, and every reply sent, is listed with the tool's name.
Turn on tool approval in your AI tool#
Most AI tools can ask you before they call a tool. Keep that on, at least for the tools that put something out or delete something:
| Tool | What it does |
|---|---|
publish_post |
Publishes a post now |
schedule_post, schedule_posts |
Schedules posts to go out |
reply_to_thread |
Replies in public, as your account |
delete_post, delete_media_subject |
Deletes; can't be undone |
- Heropost marks its reading tools as read-only, and the two delete tools as destructive. AI tools that decide when to ask by type use these marks.
- ChatGPT asks for your confirmation when it first calls a tool. Cursor asks for permission the first time it uses one. Check your tool's settings for the others.
- When your AI tool connects, Heropost also tells it to keep posts as drafts until you clearly ask for them to go out, and to tell you which accounts a post will reach before it schedules or publishes.
Watch out for prompt injection#
Prompt injection is text, hidden in something your AI tool reads, that tries to give it instructions: a comment, a direct message, a web page, a document or a file name. With Heropost connected, an AI tool that follows such text could post or reply on your accounts.
- Don't let it act on instructions it finds in comments, messages or pages. Ask it to show them to you instead.
- Review replies before they're sent. Ask for drafts of replies first, and keep Reply in the inbox off unless you need it.
- Be careful when other connectors are on in the same chat, such as web browsing or email. Content from one can steer what the tool does in Heropost.
- For tools that read untrusted content, switch off Publish and schedule, or use approvals, so nothing goes out without you.
- Check drafts before they're scheduled.
If a link leaks#
- In Heropost, open Home → Connect your AI tools → Your tools.
- Press New link on that tool, or Remove if you no longer use it. The old link stops working at once.
- If you made a new link, put it in your AI tool.
- Check Activity for anything you don't recognize. Then look at Content → Drafts, your calendar and the Social Inbox.
- Delete any posts you didn't ask for. Posts already published must be deleted on the network.
Questions#
Can an AI tool see my password or payment details?
No. Billing, sign-in and team settings aren't available to AI tools.
Can it post to accounts I didn't pick?
No. Heropost refuses any account outside Which accounts, and those accounts don't appear in its account list.
Can it delete my posts from Instagram or Facebook?
No. Deleting a post from an AI tool removes it from Heropost only. Published posts stay on the network.
Can an AI tool give itself more permissions, or make a new link?
No. Only the workspace owner or an Admin can change permissions or links, in the Heropost app.
Does Heropost see my conversations in ChatGPT or Claude?
No. Heropost only receives what your AI tool sends when it calls a Heropost tool, such as the text of a post to save.
ChatGPT says "elevated risk" and Claude warns about the server URL. Should I worry?
These are the tools' standard warnings. ChatGPT shows "elevated risk" for any connector it hasn't reviewed itself. Claude warns that anyone with the server URL can use the connector, which is true for Heropost: the link is the key. Keep it private, and use the permissions above.