# API connection: permissions and presets

Source: https://listplus.ai/en/help/ai-agents-api/api-permissions
Last updated: 2026-09-25

Every connection's **Permissions** tab controls exactly what an agent can see and do in that one list. Start from a preset, then adjust. Choosing a preset also resets Visible Columns (all visible again), Write Protection, Deduplicate by and Record Quality, and turns all research tools on — check those sections after picking one.

## Presets

| Preset             | What it turns on                                                                                                                                                                                                                                                                      |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Read Only**      | Query, count, run quality checks. No adding, editing or enrichment (research tools stay on unless you uncheck them)                                                                                                                                                                   |
| **Data Assistant** | Query, count, edit, ignore, sublists, tags, quality checks. No adding, no enrichment                                                                                                                                                                                                  |
| **Enrichment**     | Query, count, edit (empty cells only), quality checks, plus six enrichment types: Company Profile, LinkedIn Profile (by LinkedIn URL), LinkedIn URL (by Name & Company), LinkedIn Profile Search (by Name & Company), Contact Profile (by Email), Contact Profile (by Name & Company) |
| **Data Collector** | Add, query, count, ignore, sublists, tags, Company Profile, all research tools. Makes all columns visible, limits writing to typical lead columns, deduplicates by the LinkedIn column if there is one                                                                                |
| **Full Access**    | All actions including AI column filling and creating/deleting its own columns, plus the same six enrichment types (not Contact Brief)                                                                                                                                                 |
| **Custom**         | Your own combination — selected automatically once you change anything a preset doesn't match                                                                                                                                                                                         |

A brand-new connection can add, query, count, tag, ignore and sort records into sublists, look up Company Profiles, and use the research tools, including the paid ones. Editing records, AI column filling and the other enrichment types stay off until you turn them on. Review the Permissions tab before you share the URL.

## Actions

The core actions are **Add records**, **Query records**, **Count records**, **Edit records**, **Ignore records**, **Manage sublists** and **Manage tags** — add, ignore, sublists and tags stay off unless you allow them; count and query start on. Two more switches matter beyond basic data access:

- **AI column filling** — lets the agent fill a column with AI-derived values (for example gender from a name, or continent from a country).
- **Run quality checks** — ListPlus's deterministic data-quality checks; free, no credits.

Free research tools (**Google Search**, **Hacker News Search**, **Website Scrape**) and paid ones (**Reddit Search**, **Twitter/X Search**) are each their own switch, so you can allow research without allowing enrichment or vice versa — all five are on by default on a new connection. **Create columns** lets the agent add new columns to the list's schema (with an optional cap and permission to delete only columns it created itself).

## Enrichment types

Only **Company Profile** is allowed by default. Each type you check is a separate lookup with its own credit cost, shown next to the checkbox — for example Company Profile, LinkedIn Profile (by LinkedIn URL), LinkedIn Profile Search (by Name & Company), Contact Brief (by LinkedIn URL or Name & Company), and Contact Profile (by Email or by Name & Company). Only checked types are available to the agent; the exact credit amounts and when they're charged are the same as everywhere else in ListPlus — see "[What does one contact cost?](https://listplus.ai/en/help/plans-credits-billing/what-does-one-contact-cost)" and the price list. A connected **Max records per enrich request** setting caps how many rows one enrichment call can touch at once.

## Data safety controls

- **Sublist Visibility** (when your list has sublists) restricts the connection to records in the sublists you select; leave none selected to see everything.
- **Visible Columns** lets you hide specific columns from the agent entirely — it never sees or receives them. New connections hide likely email, name and phone columns automatically; you can uncheck any column to hide it, or re-check it to reveal it.
- **Write Protection** offers **Only fill empty cells** (updates can't overwrite a value that's already there) plus a column-by-column whitelist of which columns the agent is even allowed to write to; leave the whitelist empty to allow writing to any visible column.
- **Record Quality** rejects incoming records that aren't identifiable enough: **Accept all**, **Person identity required** (default — a valid email, LinkedIn URL, or name plus company), **Company identity required**, **Person or company**, or **Custom rules** where you pick specific checks yourself.

## Deduplication and default values

**Deduplicate by** picks one column (for example email); any new record whose value there already exists in the list is rejected. **Default Values** auto-fills fixed values into specific columns on every record the agent adds — useful for tagging where a batch of records came from.

**Related topics:** api-connection-overview · api-connection-setup · api-costs-and-security · what-the-ai-sees · price-list.

## FAQ

### What permission presets can I start from?

Six: Read Only, Data Assistant, Enrichment, Data Collector, Full Access, and Custom (selected automatically once your settings don't match any preset) — see the preset table above for what each one turns on.

### What actions can I individually allow or block?

Add records, Query records, Count records, Edit records, Ignore records, Manage sublists and Manage tags, plus AI column filling, running quality checks, creating columns, and each research tool (Google Search, Hacker News Search, Website Scrape, Reddit Search, Twitter/X Search) are each their own switch — turn on only what that agent needs.

### Which enrichment lookups can an agent use, and how do I turn them on?

Only Company Profile is allowed by default. On the Permissions tab's Enrichment section, check each other lookup you want to allow (for example Contact Profile by Email) — each shows its own credit cost — and set a maximum records-per-request if you want to cap how much one call can spend.

### Can I hide specific columns from the agent?

Yes. Visible Columns lets you uncheck any column so the agent never sees or receives it; new connections hide likely email, name and phone columns by default, and you can adjust that per connection.

### Can I stop the agent from overwriting data that's already there?

Yes, with Only fill empty cells, which restricts updates to blank values only. You can also whitelist exactly which columns the agent is allowed to write to at all — leaving that list empty allows writing to any visible column.

### What does "Record Quality" do?

It rejects incoming records the agent tries to add that aren't identifiable enough, based on a mode you pick: Accept all, Person identity required (the default — needs a valid email, LinkedIn URL, or name plus company), Company identity required, Person or company, or a Custom set of rules you choose yourself.

### Can I restrict a connection to only part of my list?

Yes, if your list has sublists — Sublist Visibility lets you select which ones the connection can see; with none selected, it sees the whole list.

### Can I stop duplicate records, or auto-fill a value on everything an agent adds?

Deduplicate by rejects a new record if its value in a column you pick (for example email) already exists in the list. Default Values auto-fills fixed values into chosen columns on every record the agent adds, regardless of what it sends.
