What a connection buys
A connected analytics or ad account turns an agent from a writer into an analyst. The difference between "here is some ad copy" and "here is ad copy, and the three keywords you are paying for that have never converted" is entirely a matter of what the agent can see.
Connections
| Service | Account | Access | State |
|---|---|---|---|
| Web analytics | northwind.example | Read | Connected |
| Search console | northwind.example | Read | Connected |
| Ads | Northwind Trading | Read | Connected |
| Social — network A | @northwindtrade | Read + publish | Connected |
| Social — network B | @northwindtrade | Read + publish | Expired |
Read versus publish
- Analytics and ad connections are read-only. No agent changes a budget, pauses a campaign, or edits an ad in your account.
- Social connections need publish access, because publishing is the point. That access is used only from the queue, after review.
- Connections are per workspace, so an agency managing several clients connects each client separately.
Access tokens lapse — usually after a password change, a permissions change, or a policy timeout at the provider. A queued social post fails visibly. An analytics connection is quieter: the agent still produces a confident report, drawn from less data than you think it has. Check the connections page when a number looks wrong.
What this does not do
Read-only, deliberately.
Marketing does not read your pipeline or write to your website.
The list of connectable services is fixed.
A new connection sees what the provider exposes going forward and back, not a warehouse of your history.
Questions
Do you store our credentials?
Connections are authorised tokens, held encrypted, revocable from your own account at any time.
Can we connect two ad accounts?
Yes, per workspace.
What if we revoke access?
The connection shows as expired and the agents lose that visibility.