Connectors.
You bring the tool · you grant the reads and the writes, one capability at a time.
A membrane, not a shortlist
We do not get to decide which four tools your agency runs on.
A vendor shortlist is a bet on somebody else’s stack, and it is wrong for most of the people reading it. One agency lives in Telegram. One lives in a spreadsheet. One has an HR system nobody outside their office has heard of. If a tool has an API or an MCP server, it can sit on the other side of the membrane, and the ones we happen to have built a tile for are not more connected than the one you paste in yourself.
What we own is the crossing, not the catalogue. Every connection is a written grant: which tool, which single workspace or property or folder, which capabilities, and which of those capabilities are allowed to write. More reachable tools means more the Super Agents can actually do. The price of that reach is that all of it has to be readable on one screen and revocable in one click.
Five steps, in this order
How a connection is made
The point of the order is that you read the full list of what a tool can do before anything is authorised, rather than agreeing on a provider’s screen and finding out afterwards.
Pick a tool from the list, or paste an API address or an MCP server URL. Nothing is contacted and nothing is granted at this step.
Protuno asks the tool what it can do and shows the answer back in two columns: everything it could read on the left, everything it could write on the right. Capabilities are named the same way every time, tool.resource.read and tool.resource.write, so the two columns are a fact about the tool rather than our summary of it.
Choose the one thing it may reach: which workspace, which property, which channel, which folder. There is no option that means all of it, and no way to walk outward from the anchor later.
Switch on the capabilities you want. Every write capability is off. Not off by recommendation, off by default, and it stays off until somebody with the right to grant it turns that one line on.
Protuno replays the grant back as one plain sentence and you agree to the sentence. That sentence, not a scope string, is what the receipt and the revoke screen show you later.
What one grant actually looks like
Slack, anchored to a single channel. Read on the left, write on the right, every write off until somebody turns that one line on.
What it could write
Agency · all off until you switch one onThe sentence you actually agree to. Protuno may read messages, the last 30 days of history, file names and the member list in #acme-website on the Northwind workspace. It may not read any other channel, any direct message, or any file. It may not post, reply or react, because you left all three off. Anything Protuno reads here is used to produce a finding and then dropped.
The whole rule, once
Which plan connects what
Reading someone’s Search Console cannot break their Tuesday. Posting into the channel their client reads can. That is the only line, and it is why an expensive tool can be on the cheap plan and a cheap tool can be on the dear one.
In the order we would build them
The first ten
Ranked by how much an agency gets back against how much it has to chase to switch one on. Four of the ten only ever read. Two only ever send. Nothing on this list is a gate on the rest: a tool that is not here is a URL you paste in.
The pages that lost clicks this month become a refresh list, worst first. You stop rebuilding that list by hand every quarter.
Cloudways, Kinsta, WP Engine, RunCloud. The backup a playbook takes before an update becomes the host's own snapshot rather than a plugin's best effort, which is the difference between a restore point and a hope.
The approve step happens where you already are. Reading a channel and posting an alert into your own is one thing. Posting into a channel the client reads is another, and it is priced as another.
An address per site. The client forwards the thing they were going to describe badly on a call, and it arrives attached to the right site with the right people on it. No account for them to make.
A doc becomes a formatted draft post with the images handled and the SEO fields filled in. It lands as a draft and it stays a draft. The connector can only ever see files a person handed it through Google's own picker.
A bot token, pasted once, and the site that went down tells you on your phone. No OAuth application, no verification, no quota, nothing for the client to approve.
One signed JSON payload per event to an address you own. This is the escape hatch: if we never build a tile for the thing you run, this is how a run reaches it anyway.
A task moves into Ready and the playbook attached to that list runs. When it finishes, the task closes itself with a link to exactly what changed on the site.
What the client actually asks about at the end of the month. It reads and nothing else, and it is still the dearer plan, because the grant is manual on every property and the meter is per property and unpredictable.
Ahrefs, Semrush, DataForSEO, whichever one you already pay for. You bring the key, you keep the contract, and the meter stays yours instead of being marked up through us.
Two of those look wrong until you see the reason
Search Console
It reads Google, so people expect it on the dear plan. It is on Care, in full, keywords included, and it is the cheapest connector we will ever build. The reason is onboarding, not data: the connector plugin can place the HTML verification tag on the site itself, so nobody has to chase the client for anything. At forty sites the cost that hurts is not what we pay, it is what you have to ask forty people to do. The quota is flat as well, 1,200 queries per minute per property, so it does not get dearer as a site gets bigger.
Google Docs
It runs on the drive.file scope and only that scope. That scope is non-sensitive, so it carries no annual security assessment. drive.readonly would see the whole of a client's Drive and would put us into a yearly third-party audit, so we do not ask for it. The side effect is the honest one: the connector cannot go looking for a document you did not hand it, because it genuinely cannot see one.
Six commitments, all testable
What you get to check
A connector reaches into an account that is not ours and is often not yours either. So none of these are adjectives. Each one is a thing you can go and try, and each one fails visibly if we stop doing it.
The receipt
Whoever granted the connection gets an email stating the grant in the same plain sentence they agreed to, with a revoke link that works without logging in. The client's marketing manager who clicked approve can undo it on a Sunday without asking you for a password.
One screen per site
Everything reachable on that site right now, in one list, with the last time each capability was actually used. A grant nobody has used in four months is visible as exactly that, which is usually the moment somebody turns it off.
Two logs, not one
Every connector call is written to your tenant log and to the site's own log on the client's server. You hold a copy on hardware we do not control, so our record of what we did is checkable against a record we cannot quietly edit.
Honest revocation
Revoking runs three steps: stop the schedules, destroy our stored credential, and call the provider's own revoke endpoint. We then tell you which of the three actually happened. If a provider has no revoke endpoint, or its endpoint refuses, that appears on the screen instead of a green tick.
Nothing borrowed is kept
The payload from a third-party tool is transient. The document, the message, the analytics rows: they exist in memory for the run and are never written to disk. What persists is the derived finding, which is the sentence we could defend to the client anyway.
New capabilities arrive off
When a connector update adds capabilities, they are off. An update is never a widening. If a tool grows a write we think you would want, it appears in the list switched off, with the reason, waiting for somebody to opt in.
Four, and they do not move
What a connector will never do
Publish
Nothing goes live without a person. Everything a connector produces lands as a draft, and a draft stays a draft until somebody presses the button. On every plan, forever.
Invent
We never fill in a detail about a client's business. If the document does not give the price, the opening hours or the accreditation, the draft says it is missing. It does not put something plausible in the hole.
Race you
We never touch a page a human is editing. If the post is locked, or somebody saved it in the last ten minutes, the run stops and tells you rather than winning.
Write without an undo
Every write capability ships with a defined reversal or it does not ship. Posting a Slack message has one, you delete the message. Sending an email does not, so sending email is not a write capability here, on any plan, however often it is asked for.