Security baseline
- Give each teammate an individual account.
- Use Viewer for read-only review.
- Prefer selected-workspace access when a person does not need every workspace.
- Connect providers with the minimum resources required for the workspace.
- Keep API keys and OAuth credentials out of chat, Slack, tickets, and screenshots.
- Review guardrails before enabling proposal or mutation workflows.
- Keep Review everything until the team has verified real outcomes.
- Remove former teammates, stale invites, unused MCP seats, and unrecognized OAuth sessions.
If an account may be compromised
1
Sign out every session
Go to Settings → Authentication and select Sign out everywhere.
2
Reset access
Send a password-reset link and secure the email account or identity provider used to sign in.
3
Review membership
Ask an Owner or Admin to inspect account membership, workspace grants, pending invites, and role changes.
4
Revoke external sessions
Disconnect unknown MCP agents and review provider-side OAuth installations or API keys.
5
Inspect material activity
Review tasks, approvals, notifications, and provider activity for actions that need containment or reversal.
Workspace access problems
Safe error handling
When a page says a status could not be verified, refresh before making a replacement connection. Marketer keeps last-known connection data or settings when a safe read fails; a temporary read error should not be interpreted as proof that access was removed. For provider-specific recovery, use Troubleshoot integrations.Prepare an escalation
Include only what another operator needs to reproduce the issue:- workspace and account name;
- your role and whether access is account-wide or selected;
- page and exact error text;
- expected and actual behavior;
- last known successful action and time; and
- a sanitized screenshot.