AI connector (MCP)

Safety, confirmations and fair use

What an assistant can and cannot do on your behalf, the confirmation step, and the rate limits.


An assistant acting on your account is convenient and, without guardrails, risky. These are the guardrails.

The confirmation step

Seven actions never happen on the first call:

  • deleting a search profile,
  • dismissing a match as not relevant,
  • turning a daily alert off,
  • turning the digest off,
  • inviting a member (it emails someone and uses a seat),
  • cancelling a pending invitation,
  • changing a member's role, above all promoting someone to owner, which transfers the organization.

Asked to do one of these, the connector performs nothing and returns a preview of what would happen. Only an explicit second call with your confirmation executes it. A model that ignores the instructions therefore still cannot silently delete anything.

Additive actions (starring, noting, creating a profile, turning an alert on) run directly, because they are harmless and reversible.

The app's roles apply unchanged: an assistant connected by a member cannot edit profiles or invite people, and only the owner's assistant can change roles. Buying seats or a plan is not possible through the connector at all; when a limit is reached, the assistant explains it and links to the public pricing page.

What is recoverable

  • Unstarring keeps your note.
  • Replacing a note returns the previous text, so it can be restored in the same chat.
  • Dismissing a match can be undone completely, including the profile edits it made.
  • Deleting a search profile archives it.

What an assistant cannot do

  • Act in an organization you are not a member of. Membership is verified on every call.
  • Read another user's favorites or notes. Those are strictly personal.
  • Fetch a document by arbitrary URL. Documents are addressed by their position in a tender's document list, which is what keeps the connector from being used as a general-purpose fetcher.
  • Submit a bid.
  • Buy or change a plan, or see your invoices.

Rate limits and fair use

Normal use never hits these. They exist to keep one runaway loop from degrading the service:

  • Around 240 calls per minute per user, with a burst allowance.
  • Reading documents is metered separately: about 10 reads per minute and a daily download budget, because each cache miss pulls bytes from a third-party portal. Reading an already extracted document is nearly free.
  • Matching runs obey the same cooldown and daily budget as in the app, see Refreshing and limits.

When a limit is hit you get a clear error, not a silent truncation. Wait a moment and continue.

Was this page helpful?

On this page