AI Visibility Platform Access Control: SSO, Team Roles, and Scoped API Keys
The access policy we run across client GEO programs: who gets a seat, who gets a report, and why write keys live on exactly one seat.
An agency workspace holding a dozen clients' AI visibility data is a concentration of risk that deserves an actual policy, not vibes. Ours fits on a page, has survived several client security reviews, and is reproduced here because most of the questions we get about tooling are secretly questions about access.
We run client programs on Promptwatch agency plans, which carry 10 seats and unlimited projects. The seat number sounds small for an agency until you see how few humans actually need a platform login. Our split:
Seats go to people who operate the platform: the strategist who manages prompt lists, the analyst who reads citations and crawler logs, the one person connected to client CMSes. That is usually three to five humans.
Reports go to everyone else, on both sides of the relationship. Clients get branded Looker Studio dashboards wired to read-only keys scoped to their own project. Internal account leads get the same. Nobody gets a login because they "might want to poke around." Poking around is what Agent Chat and the weekly review are for.
The key policy, verbatim
Every key is read-only unless it can name the specific write it performs. In practice that means: Looker connectors get read-only project keys, one per client, so a leaked report credential can read one client's dashboard and nothing else. MCP sessions in Claude and Cursor get read-only keys too, and Promptwatch's MCP server hides write tools entirely on a read-only key, so the chat physically cannot bulk-create prompts or touch a draft. We verified that behavior before trusting it, and you should too.
The single exception is the CMS seat. Publishing GEO content to a client's Webflow requires write capability, so exactly one seat holds a write key, and that key rotates the day that person changes role or leaves. Not at the monthly review. That day. Rotation does not break the Looker reports because they were never on the write key, which is the quiet payoff of the whole policy.
Org-level keys exist for the rare tooling that spans clients, and they are still read-only. A freelancer never holds one. The longer write-up with the reasoning is in read-only API keys for Looker and MCP.
SSO, and when clients should care
Promptwatch gates SSO behind its Enterprise tier, as does everyone in this category as far as anything published shows. Our advice to clients is unglamorous: if your security policy mandates SSO for vendor tools, that is an enterprise conversation and a real budget line, so surface it in procurement week one. If it does not, read-only OAuth scopes get you most of the practical safety. The outward connections we set up, Search Console via read-only OAuth and Slack via an org-owner grant, have passed every client review so far without escalation. Google's AI features documentation is the page we send when a security review asks what "AI search data" even means. It is Google's description of Overviews and related features, not a Promptwatch login.
One habit that costs nothing: keep an access inventory per client. Which seats, which keys, which scopes, which Looker shares. When a client's security team asks, you answer in an hour instead of a week, and when an engagement ends, offboarding is a checklist instead of an archaeology dig.
FAQ
Who gets a Promptwatch seat?
People who operate the platform: the strategist who manages prompt lists, the analyst who reads citations and crawler logs, the one person connected to client CMSes. That is usually three to five humans. Everyone else gets a Looker report.
Where does SSO live?
Enterprise, alongside white-label and dedicated support. If a client's policy mandates SSO, surface it in procurement week one. It is a real budget line.
How many write keys do we issue?
One, on the CMS-connected seat. Looker and MCP get read-only keys. Rotate the write key the day that person changes role or leaves.
If you want your GEO tooling access reviewed against this policy, or set up correctly from the start, write to hello@1001seomedia.com.