Each token does only what it was granted: by area, resource and action.
The four layers
Which data. A token only reaches the companies chosen when it was created: its primary account,
other companies administered by whoever created it and, if chosen, whole groups, which include their subsidiaries
(also those added later). Choosing one company does not add the rest of its group. Routes with a
companyId check that the company is within that scope; otherwise they respond 403 or
404 without revealing anyone else's data. GET /auth/whoami returns the list of companies
a token reaches (Getting started).
What it can do. Permissions look like area:resource.action, for example
sales:invoices.read. Each route requires one, and the token must hold a grant that covers it.
Conditions. Expiry date, allowed IP addresses and access to personal data
(Authentication).
Quotas. Requests-per-minute limit for the token, within that of the account and the user
(Rate limits).
Levels
When you create a token you choose a level for each area or resource:
Level
What it grants
None
Nothing.
Read
Reads (read), including file downloads.
Write
Read, plus create, update and delete (create, update, delete). It does not include critical actions.
Full
Everything above and the critical actions.
Write does not imply Read: the Write level on screen stores both grants, the read one and the write one.
Grant grammar
A token stores a list of grants. From the broadest to the most specific:
Grant
Opens
Level
area:*
The whole area, critical actions included.
Full on the area
area:*.read
The area's reads.
Read on the area
area:*.write
Create, update and delete across the area, without critical actions.
Write on the area
area:resource.*
The whole resource, critical actions included.
Full on the resource
area:resource.write
Create, update and delete on the resource, without critical actions.
Write on the resource
area:resource.action
One specific action.
Advanced
A client token only accepts grants that open permissions from the public catalogue. If a grant would open
something internal to BMC, it is rejected in full rather than trimmed silently.
Critical actions
Beyond read, create, update and delete, some actions are irreversible or have an effect outside the platform:
issuing an invoice, filing a return with the tax authority, sending a document to the end customer, voiding,
merging, posting to the ledger or reconciling. These are the critical actions.
The Write level does not cover critical actions. Only Full (area:* or
area:resource.*) or the exact action name, chosen under Advanced, opens them. They are flagged in the catalogue.
Complete catalogue
The public catalogue has 154 permissions across 14 areas and
50 resources; 28 are critical actions. Resources
flagged "Personal data" return tax ID, IBAN, phone, date of birth or address, which come back masked if the token
does not have the personal data permission. Adding a permission to the catalogue grants nothing to anyone: each
token stores only what was chosen when it was created.