Skip to content

What can an AI agent do in my Mindstamp account, and how do I control it?

AI agents act as the signed-in user, with scopes you approve. High-impact actions need confirmation, actions are logged, and the owner can revoke access.

Updated

Short answer

An AI agent connected through Mindstamp MCP acts as the user who signed in, within that user's permissions and the scopes they approved. Viewer identities and deletions need their own scopes, high-impact actions need confirmation, and every action is logged. The account owner can turn AI off or revoke any agent at once.

Scopes

  • read: list and read videos, interactions, transcripts and aggregate results.
  • write: create videos and change interactions, links, captions, assets and settings. Needs a plan with write access.
  • read:viewers: viewer identities (names and emails), raw report rows and personalized-link recipients.
  • destructive: delete videos and other confirmed, high-impact actions.
  • An API token used as a bearer token has full access, the same as the REST API. Use OAuth when you want to limit scopes.

Built-in safeguards

  • AI features are off until the organization owner turns them on. Every change sends a confirmation email.
  • The agent acts as the connecting user. It cannot do anything that user cannot do.
  • High-impact tools need an explicit confirmation from the agent after a person approves: publishing, access changes, account branding, upload preparation and video deletion.
  • Each action gets an action ID. Many changes can be undone. The agent can check which ones before it promises an undo.
  • Transcripts, titles and viewer answers are treated as data, never as instructions to the agent.
  • Each user can run 30 agent actions a minute.

Review and revoke access

  • The AI settings page (app.mindstamp.com/ai-settings) lists Connected agents and API tokens. Select Revoke to cut access at once.
  • The same page shows Recent agent actions, so you can see what each agent did.
  • Select Turn off AI features to stop Max and all Mindstamp MCP connections for the organization.
  • OAuth access tokens expire after one hour. Clients refresh them while the connection stays approved.
  • Developers can revoke a token with a POST request to https://app.mindstamp.com/oauth/revoke.

Good practice

  • Approve only the scopes the task needs. Leave read:viewers and destructive off unless you need them.
  • Ask the agent to show a preview before it publishes a video.
  • Do not paste API tokens into a chat with the agent. Keep them in the client's credential settings.

Go further

Support

Still need an answer?

Send the video link and what you see, and the Mindstamp team will help.

New to Mindstamp? Start Free Trial.