---
title: Permissions and security
description: >-
  It acts as you, and only as you. Every request runs with your Survicate
  permissions. If you cannot open a folder in Survicate, the assistant cannot
  see the surveys in it.
source_url:
  html: 'https://developers.survicate.com/mcp/security/'
  md: 'https://developers.survicate.com/mcp/security.md'
---
# Permissions, privacy, and security

**It acts as you, and only as you.** Every request runs with your Survicate permissions. If you cannot open a folder in Survicate, the assistant cannot see the surveys in it. If your Research Hub role is read-only, the assistant cannot save notes or start projects for you.

**One workspace per connection.** You choose the workspace when you approve, and the connection stays bound to it. To work with another workspace, connect again.

**No API keys.** You sign in to Survicate and approve on a Survicate screen. Nothing is pasted into the assistant.

**Access follows your account.** If you leave the workspace or your account is blocked, the connection stops working within an hour. Changing your password, email, or two-factor setting also ends the connection, and you simply approve it again. For safety, every connection asks for re-approval after 90 days.

**Disconnect any time.** Remove Survicate in your assistant's connector or plugin settings. In Claude that is **Customize**, then **Connectors**, then **Connected**; in ChatGPT it is **Customize**, then **Plugins**, then **Uninstall**.

**Regulated workspaces stay out.** Workspaces flagged as HIPAA-regulated cannot be connected to AI assistants.

**Your data goes to the assistant you chose.** Survicate does not filter or redact what the assistant asks for. It receives the same data you would see in the panel, which can include personal details a respondent typed into an answer. What the assistant's provider does with that data is governed by your agreement with them, so check your company's policy before connecting.

**Admin controls.** Survicate does not yet offer a switch to stop members from connecting. Most assistants let an administrator decide which connectors are available, so use that to manage access for now.
