Connectors.

You bring the tool · you grant the reads and the writes, one capability at a time.

A membrane, not a shortlist

We do not get to decide which four tools your agency runs on.

A vendor shortlist is a bet on somebody else’s stack, and it is wrong for most of the people reading it. One agency lives in Telegram. One lives in a spreadsheet. One has an HR system nobody outside their office has heard of. If a tool has an API or an MCP server, it can sit on the other side of the membrane, and the ones we happen to have built a tile for are not more connected than the one you paste in yourself.

What we own is the crossing, not the catalogue. Every connection is a written grant: which tool, which single workspace or property or folder, which capabilities, and which of those capabilities are allowed to write. More reachable tools means more the Super Agents can actually do. The price of that reach is that all of it has to be readable on one screen and revocable in one click.

Five steps, in this order

How a connection is made

The point of the order is that you read the full list of what a tool can do before anything is authorised, rather than agreeing on a provider’s screen and finding out afterwards.

01
Point

Pick a tool from the list, or paste an API address or an MCP server URL. Nothing is contacted and nothing is granted at this step.

02
See

Protuno asks the tool what it can do and shows the answer back in two columns: everything it could read on the left, everything it could write on the right. Capabilities are named the same way every time, tool.resource.read and tool.resource.write, so the two columns are a fact about the tool rather than our summary of it.

03
Anchor

Choose the one thing it may reach: which workspace, which property, which channel, which folder. There is no option that means all of it, and no way to walk outward from the anchor later.

04
Tick

Switch on the capabilities you want. Every write capability is off. Not off by recommendation, off by default, and it stays off until somebody with the right to grant it turns that one line on.

05
Agree

Protuno replays the grant back as one plain sentence and you agree to the sentence. That sentence, not a scope string, is what the receipt and the revoke screen show you later.

What one grant actually looks like

Slack, anchored to a single channel. Read on the left, write on the right, every write off until somebody turns that one line on.

What it could read

Care and Agency
slack.channel.readmessages in one channel, the one you anchored to.
On
slack.channel.historythe last 30 days of that channel, so a reply has the thread behind it.
On
slack.file.metathe names and sizes of files posted there. Not the files.
On
slack.member.listwho is in the channel, so an approval can name a person.
On
slack.emoji.readoffered by Slack, off, nothing needs it.
Off
slack.workspace.channelsrefused by us. It lists every other channel, which is the opposite of an anchor.
Refused by us
5 offered · 4 on · 1 refused at our end, not yours

What it could write

Agency · all off until you switch one on
slack.channel.postone message per run. Undo: delete the message.
Off
slack.thread.replyanswer inside the thread it started. Undo: delete the reply.
Off
slack.message.reactmark a run as done. Undo: remove the reaction.
Off
slack.channel.createrefused by us. Nothing a Super Agent does needs a new channel.
Refused by us
slack.member.inviterefused by us. Adding a person to a client's workspace is not a maintenance job.
Refused by us
3 offered · 0 on · 2 refused at our end, not yours

The sentence you actually agree to. Protuno may read messages, the last 30 days of history, file names and the member list in #acme-website on the Northwind workspace. It may not read any other channel, any direct message, or any file. It may not post, reply or react, because you left all three off. Anything Protuno reads here is used to produce a finding and then dropped.

The whole rule, once

Which plan connects what

ReadPull facts in. Search Console clicks, a task list, a document, a host's backup history.
Care: Any toolAgency: Any tool
NotifyPush a message out to you. Telegram, a webhook into whatever you already run, an alert in your own channel.
Care: Any toolAgency: Any tool
Write backChange something in the other tool. Close the task, post in the client's channel, put the draft in the folder.
Care: NoAgency: Any tool
A connector we do not shipYour own API or MCP server, described once and then treated like any other connection.
Care: NoAgency: Yes

Reading someone’s Search Console cannot break their Tuesday. Posting into the channel their client reads can. That is the only line, and it is why an expensive tool can be on the cheap plan and a cheap tool can be on the dear one.

In the order we would build them

The first ten

Ranked by how much an agency gets back against how much it has to chase to switch one on. Four of the ten only ever read. Two only ever send. Nothing on this list is a gate on the rest: a tool that is not here is a URL you paste in.

01
Google Search Console

The pages that lost clicks this month become a refresh list, worst first. You stop rebuilding that list by hand every quarter.

Read onlyCare
02
Host APIs

Cloudways, Kinsta, WP Engine, RunCloud. The backup a playbook takes before an update becomes the host's own snapshot rather than a plugin's best effort, which is the difference between a restore point and a hope.

Reads and writesCare to read, Agency to act
03
Slack

The approve step happens where you already are. Reading a channel and posting an alert into your own is one thing. Posting into a channel the client reads is another, and it is priced as another.

Reads and writesCare to read, Agency to post
04
Inbound email

An address per site. The client forwards the thing they were going to describe badly on a call, and it arrives attached to the right site with the right people on it. No account for them to make.

Read onlyCare
05
Google Drive, on the drive.file scope

A doc becomes a formatted draft post with the images handled and the SEO fields filled in. It lands as a draft and it stays a draft. The connector can only ever see files a person handed it through Google's own picker.

Reads and writesCare to read, Agency to write back
06
Telegram

A bot token, pasted once, and the site that went down tells you on your phone. No OAuth application, no verification, no quota, nothing for the client to approve.

Sends onlyCare
07
Outbound webhook

One signed JSON payload per event to an address you own. This is the escape hatch: if we never build a tile for the thing you run, this is how a run reaches it anyway.

Sends onlyCare
08
ClickUp

A task moves into Ready and the playbook attached to that list runs. When it finishes, the task closes itself with a link to exactly what changed on the site.

Reads and writesCare to read, Agency to close
09
Google Analytics 4

What the client actually asks about at the end of the month. It reads and nothing else, and it is still the dearer plan, because the grant is manual on every property and the meter is per property and unpredictable.

Read onlyAgency
10
A keyword data source, on your own key

Ahrefs, Semrush, DataForSEO, whichever one you already pay for. You bring the key, you keep the contract, and the meter stays yours instead of being marked up through us.

Read onlyAgency · bring your own key

Two of those look wrong until you see the reason

Search Console

It reads Google, so people expect it on the dear plan. It is on Care, in full, keywords included, and it is the cheapest connector we will ever build. The reason is onboarding, not data: the connector plugin can place the HTML verification tag on the site itself, so nobody has to chase the client for anything. At forty sites the cost that hurts is not what we pay, it is what you have to ask forty people to do. The quota is flat as well, 1,200 queries per minute per property, so it does not get dearer as a site gets bigger.

Google Docs

It runs on the drive.file scope and only that scope. That scope is non-sensitive, so it carries no annual security assessment. drive.readonly would see the whole of a client's Drive and would put us into a yearly third-party audit, so we do not ask for it. The side effect is the honest one: the connector cannot go looking for a document you did not hand it, because it genuinely cannot see one.

Six commitments, all testable

What you get to check

A connector reaches into an account that is not ours and is often not yours either. So none of these are adjectives. Each one is a thing you can go and try, and each one fails visibly if we stop doing it.

The receipt

Whoever granted the connection gets an email stating the grant in the same plain sentence they agreed to, with a revoke link that works without logging in. The client's marketing manager who clicked approve can undo it on a Sunday without asking you for a password.

One screen per site

Everything reachable on that site right now, in one list, with the last time each capability was actually used. A grant nobody has used in four months is visible as exactly that, which is usually the moment somebody turns it off.

Two logs, not one

Every connector call is written to your tenant log and to the site's own log on the client's server. You hold a copy on hardware we do not control, so our record of what we did is checkable against a record we cannot quietly edit.

Honest revocation

Revoking runs three steps: stop the schedules, destroy our stored credential, and call the provider's own revoke endpoint. We then tell you which of the three actually happened. If a provider has no revoke endpoint, or its endpoint refuses, that appears on the screen instead of a green tick.

Nothing borrowed is kept

The payload from a third-party tool is transient. The document, the message, the analytics rows: they exist in memory for the run and are never written to disk. What persists is the derived finding, which is the sentence we could defend to the client anyway.

New capabilities arrive off

When a connector update adds capabilities, they are off. An update is never a widening. If a tool grows a write we think you would want, it appears in the list switched off, with the reason, waiting for somebody to opt in.

Four, and they do not move

What a connector will never do

Publish

Nothing goes live without a person. Everything a connector produces lands as a draft, and a draft stays a draft until somebody presses the button. On every plan, forever.

Invent

We never fill in a detail about a client's business. If the document does not give the price, the opening hours or the accreditation, the draft says it is missing. It does not put something plausible in the hole.

Race you

We never touch a page a human is editing. If the post is locked, or somebody saved it in the last ten minutes, the run stops and tells you rather than winning.

Write without an undo

Every write capability ships with a defined reversal or it does not ship. Posting a Slack message has one, you delete the message. Sending an email does not, so sending email is not a write capability here, on any plan, however often it is asked for.