An integration can give Mantle access to data or actions in another app. Review that access with the same care you would
use for any teammate or automation.
Your connection stays yours
A connected app account belongs to the person who connected it. Sharing an agent does not give every workspace member
your sign-in or silently let them act as you.
When a teammate runs a shared agent, Mantle uses a connection available to that teammate when the tool requires one. If
they do not have the required app connected, the tool may ask them to connect it or stop the run.
Background tasks need an owner
An automatic task uses the connection configured for that task. If the connection expires, loses permission, or is
disconnected, the task may pause or fail.
After reconnecting:
- review the permissions in the connected app;
- confirm the agent still has only the tools it needs;
- use Run now to test the task;
- turn automatic runs back on only after the result is correct.
An event missed while a connection was unavailable may not be processed later. Check the task history and the source app
before retrying work that changes outside data.
Limit what an agent can do
- Connect the smallest suitable account, team, project, or database.
- Prefer read access when the job only needs to look up information.
- Select individual tools instead of enabling every available action.
- Require human review before sending messages, changing money, deleting data, or publishing content.
- Test with non-sensitive data and a reversible action.
The connected app remains the source of truth for the permissions it grants. You can usually review or revoke Mantle’s
access from that app as well as from Mantle.
Credentials and data
Mantle protects saved connection credentials and does not show secret values back in normal app screens. Never paste an
access key into a channel, chat, canvas, agent instruction, or public support post.
Connected-app results become part of Mantle when an agent posts them in a chat, channel, or task result. The access
rules of that Mantle location then apply to the copied result.
Public links do not grant app access
Sharing a chat or canvas publicly does not give a visitor your connected account. However, any connected-app information
already written into the shared content can be visible. Review the entire item before publishing it.
Disconnect an app
Go to Settings → Integrations, open the app, and disconnect it. Then review agents and tasks that used its tools or
triggers. Pause or update them so failures do not fill a channel with repeated alerts.
If you think a credential was exposed, revoke it in the connected app first, create a replacement if needed, and contact
your organization admin or Mantle support.
Do not approve a sign-in screen or permission request you do not understand. Ask your organization admin before
connecting regulated, production, financial, or customer-data systems.