SECURITY & PERMISSIONS

Is it safe to connect an AI agent to your social media?

It is safe when the connection is scoped and reversible. ZocialOne issues a per-workspace API key, never your social platform passwords. Nothing publishes without your approval, every action is logged, and you can delete the key under Ask Zoe → API Keys at any time.

7-day free trial✓ Included on every plan✓ No credit card needed
How it works

Six things that make this safe to turn on

The honest version: an AI assistant with publishing rights is a real risk surface. Here is what constrains it.

Your AI never sees your passwords

Your social accounts stay connected to ZocialOne through each platform’s official OAuth flow. The MCP connection sits between your AI client and ZocialOne — it never receives platform credentials, and it cannot read them.

Scoped to one workspace

The API key is scoped to one workspace. It can reach the brands and channels in that workspace and nothing else. Running an agency? Each client workspace gets its own URL, so one connector cannot cross into another client’s accounts.

Approval before publish

Your AI proposes; a human confirms. Content drafted through MCP lands in your approval queue by default, so nothing goes live by accident because a model misread a prompt. Teams that want speed can switch specific channels to auto-publish.

Every action is logged

Each MCP tool call is recorded with the timestamp, the tool used, the brand it touched and the result. If you need to answer “who scheduled this and when”, the audit log answers it — which is also what your security reviewer will ask for.

Revoke in one click

Delete the key under Ask Zoe → API Keys and every client using it loses access immediately. Rotating a key does not disconnect your social channels or affect anything already scheduled.

Least privilege on outbound apps

The 100+ business apps Zoe can connect to are authorised one at a time, by you, with the narrowest scope each vendor offers. Connecting your CRM does not grant access to your payment processor.

Exactly what it can reach

What the connection can and cannot do

Worth reading in full before you connect a client — and worth sending to whoever signs off on tooling.

Channels a connector can reach in that workspace
InstagramFacebookLinkedInLinkedInYouTubeGoogle Business ProfileGoogle Business ProfilePinterestThreads
CanPublish and schedule posts to connected channels
CanRead performance and analytics for your own accounts
CanRead and reply to comments and Google Business reviews in your inbox
CanList the brands and channels in that one workspace
CannotRead your social platform passwords
CannotReach brands or channels in a different workspace
CannotChange your billing, plan or account owner
CannotPublish without your approval, unless you turn that on
The other direction

What about the 100+ connected apps?

The integrations directory works the other way round: Zoe reaching out to your CRM, email platform or analytics tool. That is a separate grant, and it follows the same principle.

You authorise each app individually, through that vendor’s own OAuth flow, at the narrowest scope they offer. Connecting your CRM does not grant access to your payment processor. Each connection can be revoked on its own without affecting the others, and none of them are enabled by default.

If your organisation restricts which third-party tools can hold tokens, this is the page to send them — and we are happy to answer a security questionnaire.

FAQ

Frequently Asked Questions

It is safe when the connection is scoped and reversible. ZocialOne issues a per-workspace API key, never your social platform passwords. Nothing publishes without your approval, every action is logged, and you can delete the key under Ask Zoe → API Keys at any time.

You do not give it access to the accounts themselves. You give it a scoped MCP URL for your ZocialOne workspace. Your social channels stay connected to ZocialOne through each platform’s official OAuth flow, and the AI client only ever talks to ZocialOne.

Delete the key under Ask Zoe → API Keys. Access stops immediately for every client using it. Your social channels stay connected and anything already scheduled is unaffected. Then check the audit log to see exactly which actions ran.

Yes. Every MCP tool call is logged with a timestamp, the tool used, the brand it touched and the result — so “who scheduled this and when” always has an answer.

No, provided each client sits in its own workspace. The MCP URL is scoped per workspace, so a connector authorised for one client cannot see another’s brands or channels.

Not by default. Content created through MCP goes into your approval queue, so you confirm before anything publishes. You can switch specific channels to auto-publish if you would rather trade the checkpoint for speed.

They run in opposite directions. The MCP server lets your AI assistant operate ZocialOne. The integrations directory lets Zoe reach out to 100+ other business tools — your CRM, email platform, SEO suite and analytics — on your behalf. Most platforms do one or the other. ZocialOne does both.

Yes. Zoe generates content natively in Hindi, Telugu, Tamil, Marathi, Bengali, Kannada and Gujarati, alongside English and Hinglish — generated in the language, not translated into it afterwards.

Scoped, logged, and revocable in one click

Connect it, try it on one brand, and revoke it if you do not like it.

7-day free trial✓ Included on every plan✓ No credit card needed