Skip to Content

Connect an external assistant to your system

A secure access point that lets an external assistant read or act, with your own rights and a log.
October 2, 2026 by
Connect an external assistant to your system

More and more business owners want an external assistant to be able to look up their management data to answer a question or prepare a document, without opening their system to just anyone. This application exposes a dedicated access point, with a revocable key, a list of allowed data and a log of every call.

Who the application is for

For business owners and managers who want to connect an external assistant — conversational, coding or office-related — to their management data, while keeping control of what it can see and do.

What the application does

  • Opens a dedicated access point for an external assistant connector, switched off by default until it is turned on deliberately.
  • Authenticates each assistant with its own revocable key, which can carry an expiry date and stays tied to a real user.
  • Makes every call act with that user's own rights: groups, access rules and separation between companies apply without exception.
  • Exposes no data until it has been added to a whitelist, with the detail of what is allowed — read, write, create, delete — and an optional restriction.
  • Keeps a log of every call: the action requested, the records touched, the duration, the originating address and any error.
  • Limits the number of calls per minute for a given key, so a runaway assistant does not overload your system.

Day to day

  1. Turn on the access point in the general settings, and leave write operations disabled to start with.
  2. Add a first data type to the whitelist, read-only, to validate the connection without risk.
  3. Create a key on the dedicated user's profile, copy it immediately since it is only shown once, then give it to the external assistant.
  4. Review the log after the first calls to see what the assistant actually did.
  5. Open up writes and widen the whitelist once reading has been validated, always with a user whose rights are deliberately narrow.

What the application does not do

  • It opens no anonymous access: without a valid key, the access point returns nothing useful.
  • It does not itself run any language processing and carries no cost related to the assistant: that is handled by the external client.
  • It exposes no data by default, including after an update.
  • It never widens a user's rights: it can only restrict them further.

Getting started

Create a dedicated user with deliberately narrow rights rather than using an administrator account, choose a first data type to expose read-only with it, and keep writes disabled until the log has shown you what the assistant actually does. Then give that user only the rights they actually need, since every call stays bounded by the rights of the user holding the key.

Going further

To find out whether this application suits your business and how to activate it, compare the plans or write to us.

Compare the plans

Write to us

WooCommerce import: bringing your catalogue across
A tooled catalogue import to bring in WooCommerce products, variations, customers and orders.