Review effective access before asking them to connect an AI client.
Change group access
Open the group and identify the business workflow.
Prefer individual tool grants when the full app is unnecessary.
Add explicit restrictions for tools the group must not use.
Review a representative member's effective access.
Verify a bounded read in Audit.
Rotate a shared credential
Create the replacement in the provider.
Preserve the same tenant and least-privilege scope.
Update the app in Stackyapper.
Verify a read and check Audit.
Revoke the old provider credential.
Offboard a user
Remove or suspend the company identity using the authoritative identity
system.
Remove direct Stackyapper membership if it is not provisioned.
Revoke the user's AI and API clients.
Revoke personal app authorizations.
Review recent Audit activity and preserve required records.
Respond to a denied or failed call
Use Audit and investigation. Fix the
narrowest failed layer—connection, availability, policy, confirmation, or
provider health—then verify with a read.