DocsAI Assistant (MCP)What it can do & security

What it can do & security

Everything an AI assistant connected to Lead Distro AI can read and change, grouped by area, plus the permission model, rate limits, what it can never do (move money), and how to disconnect an assistant or revoke an API key.

Last updated:

Once connected, you ask the assistant in plain English and it uses tools scoped to your organization. What it can do depends on the permissions you granted.

Permission levels

When you connect an assistant you grant it one or more permission levels, and each level unlocks a group of tools. You can connect a read-only assistant just for reporting, or a full one that also sets things up. The capability groups below are tagged with the level they need.

PermissionWhat it unlocks
Read & reportingLook at everything: campaigns, buyers, suppliers, leads, stats, and profit reports. Changes nothing.
Manage campaigns & fieldsCreate and change campaigns, fields, filters, buyers, suppliers, delivery, ping-post, automations, and the Partner Portal.
Lead operationsSend $0 test leads, post buyer conversions back, and reconcile lead outcomes.

Write actions run immediately when you ask for them. There is no separate approval step like the in-app assistant has, so review what you are asking for before you send it.

What you can do

Everything the assistant can do, grouped by area. The Needs column is the permission level each capability requires (see above). Read is view-only; Manage and Lead ops make changes.

AreaYou can ask it toNeedsExample
Reports & insightsList and inspect campaigns, buyers, and suppliersRead"List my active campaigns."
Reports & insightsPull lead counts, revenue, cost, and profit for any date rangeRead"What was my profit last week?"
Reports & insightsBreak leads down by campaign, buyer, supplier, status, or stateRead"Break down last month's leads by state."
Reports & insightsReview a campaign's full P&L with per-buyer and per-supplier detailRead"How is Auto Accident doing, by buyer?"
Reports & insightsList or open individual leads (contact details stay hidden unless you ask)Read"Show me yesterday's rejected leads."
Reports & insightsExplain why a lead was routed the way it wasRead"Why did this lead go to Acme?"
Reports & insightsCheck setup progress, or get the post instructions a supplier needsRead"Give Acme the post spec for Solar."
Campaigns & fieldsCreate a campaign or change its settingsManage"Create a campaign called Auto Accident."
Campaigns & fieldsAdd lead fields, or rewrite the whole field listManage"Add a required phone field."
Campaigns & fieldsSet inbound filters that accept or reject incoming leadsManage"Reject leads from outside California."
Campaigns & fieldsTurn a campaign into a ping-post exchangeManage"Make Solar ping-post with a 20% margin."
BuyersCreate a buyer or update its detailsManage"Add a buyer called Acme."
BuyersAdd a buyer to a campaign with price, priority, caps, and state filtersManage"Add Acme to Solar at $40, 50 a day, CA only."
BuyersSet delivery (webhook, email, Google Sheets, SMS, GoHighLevel) and which fields to sendManage"Deliver to Acme by webhook with name and phone."
BuyersPause, activate, or change pricing, caps, and billing model (per lead or per conversion)Manage"Switch Acme to pay only on conversion."
BuyersConfigure a buyer's real-time bid (ping) in a ping-post campaignManage"Set Acme's ping endpoint and bid field."
SuppliersCreate a supplier or update its detailsManage"Add a supplier called FB Ads."
SuppliersAdd a supplier to a campaign with a cost per lead and capsManage"Add FB Ads to Solar at $12 per lead."
SuppliersSet how cost is calculated (flat, variable, ad-account spend, or revenue share)Manage"Pay FB Ads 30% of each lead's revenue."
SuppliersPause, resume, or re-cap intake from a supplierManage"Cap FB Ads at 200 leads a day."
AutomationsSet up a rule on lead events that sends a webhook, email, Slack, or Google Sheets rowManage"Slack me when a lead is accepted."
Partner PortalTurn on the Partner Portal for a buyerManage"Enable the portal for Acme."
Partner PortalAdd or invite portal members, or see who already has accessManage"Invite ops@acme.com to Acme's portal."
Partner PortalSet the portal's return policyManage"Let Acme request returns within 7 days."
Testing & outcomesSend a $0 test lead to confirm routing and delivery workLead ops"Send a test lead through Solar."
Testing & outcomesRun a $0 ping-post dry run to see every buyer's bidLead ops"Test the ping-post exchange on Solar."
Testing & outcomesPost a buyer's conversion back, or mark a delivered lead not qualifiedLead ops"Mark lead as converted."
LeadProsper importPreview what would be migrated, changing nothingRead"Preview a LeadProsper import."
LeadProsper importRun the import after you review the plan (buyers arrive paused)Manage"Go ahead and import it."

What it can never do

No matter how you connect, the assistant cannot move money. It cannot charge a buyer's card, refund a wallet, or send or void an invoice. Those billing actions are deliberately left out. An assistant also cannot do anything outside the one organization it is connected to.

Rate limits

Each connection is limited to 120 tool calls per minute, with a tighter cap of 30 write actions per minute. If you hit a limit, the assistant gets a clear message telling it how many seconds to wait, then it can continue. The limits are generous for normal use and exist to stop a runaway loop.

Disconnect or revoke access

Browser sign-in (Claude.ai, desktop, or Claude Code): go to Settings, then API Keys, and find the Connected AI assistants card. Click Revoke next to the assistant you want to disconnect. It loses access right away and would have to be authorized again.

API key: go to Settings, then API Keys, and click Revoke on any key. The key stops working within a minute. Revoke a key the moment a teammate leaves or you suspect it has leaked, then create a new one.

Frequently Asked Questions

Is it safe to let an AI assistant manage my account?
Every connection is scoped to one organization and only does what its permissions allow. Money movement (charging cards, wallet refunds, invoices) is never exposed at all. You can revoke any connection or key instantly, and only admins can create or revoke them. As with any credential, share keys carefully and revoke them if they leak.
What can the assistant not do?
It cannot charge a buyer's card, refund a wallet, or send or void an invoice. Those billing actions are deliberately left out of the connector. It also cannot do anything outside the organization it is connected to.
Which AI assistants can connect to Lead Distro AI?
Any client that supports the Model Context Protocol (MCP) over HTTP. For one-click browser sign-in, use Claude.ai, the Claude desktop app, or Claude Code. For Cursor, Windsurf, and other JSON-config clients, add the endpoint https://mcp.leaddistro.ai/mcp and pass an API key as a bearer token. Headless setups like scripts and scheduled jobs also use an API key.
How do I disconnect an assistant?
For browser sign-in, go to Settings, then API Keys, and click Revoke under Connected AI assistants. For an API key, click Revoke on the key. Either one cuts off access.

If you have any questions, send us an email at support@leaddistro.ai