Three checks on the consent screen
Direct link- Application: recognize the application where you started the connection.
- Account: use rights that match the task you want to delegate.
- Organization: select the organization the assistant should access.
The server rechecks effective rights. A connection does not bypass later changes to account permissions. A vehicle’s presence on the public marketplace gives no access to another organization’s internal inventory or customer records.
The actual Galerie Auto screen labels remain in French. This English guide does not imply an English product interface.
Permissions and a request in the chat
Direct linkConsent covers ten permissions across five families:
- Inventory:
vehicles:readandvehicles:write. - Customers:
clients:readandclients:write. - Calendar:
agenda:readandagenda:write. - Facebook Marketplace:
repost:readandrepost:write. - Messenger:
messenger:readandmessenger:write.
The tool catalogue identifies actual effects. “Do not change anything” frames a request but does not remove a granted write permission. Muse’s approval settings and Galerie Auto’s technical permissions are separate controls. Newton operations may require further business authorizations; connecting MCP does not grant them.
Choose the minimum access needed
Direct linkA new authorization initially selects only CRM reads: Inventory, Customers and Calendar, where the account’s rights allow them. Writes and both external families are optional. To read vehicles only, keep inventory reads and remove unrelated access.
Selecting a permission adds its dependencies. Removing a prerequisite also removes dependent actions. Inventory writes require inventory reads; customer writes require customer reads. Calendar reads require customer reads, and calendar writes also require calendar reads. Marketplace reads require inventory reads; its actions also require inventory writes. Messenger reads require inventory and customer reads; its actions also require customer writes. Synchronizing a task additionally requires calendar writes and their dependencies.
A read scope is not a blanket guarantee of no internal state changes: Newton preparation or coordination status can store or reconcile state. Review the effect of the specific tool.
Historical connections retain their earlier scope, bounded by current account rights. The new default is not applied retroactively. Reconnect the application to choose a new scope. OAuth’s email scope concerns identity; it does not replace these business permissions.
Remove access for an application
Direct link- Open the CRM with the account that authorized the connection.
- Open Applications connectées (French interface).
- Find the application and check its organization.
- Select Retirer l’accès (remove access) and read the result.
- Disconnect the connector in Muse’s settings too if you no longer want to use it.
Revocation invalidates MCP access for this connection. It does not reverse completed CRM changes or erase data already received by Muse. If the screen reports that MCP access is removed but OAuth cleanup is incomplete, keep those outcomes separate and follow the displayed guidance.
Check revocation with a new request
Direct linkAfter removal, request a fresh identity read through that connector. The former access should be denied or require new authorization. A previous answer still visible in Muse’s history is not a fresh read and does not prove that access remains active.
Reauthorizing is a new access decision. Review the proposed account and organization again.
Received data and conversation history
Direct linkBefore requesting customer records, decide which information the task needs. Prefer a targeted search to a CRM export. Keep contact details, internal identifiers and temporary authorization URLs out of public screenshots.
Disconnecting stops further connector exchanges; previously used information may remain in the assistant’s history or memory. Review Muse’s settings and the Galerie Auto privacy policy (French) to manage those records.
Product documentation reviewed on . Examples are requests to adapt, with no customer data or guaranteed outcome.
Additional sources: