Skip to main content
Every connection between your workspace and a connected Account has one of three access levels. The level is chosen when the connection is created and can be reduced or revoked later. Access determines what your workspace can do with the connected Account — it does not determine billing responsibility or ownership.

Exact definitions

How access levels relate

Access levels are cumulative. Each higher level includes everything the lower levels permit:
A workspace with View only cannot use the API, install components, or operate the Book. A workspace with Integration access cannot publish a Book version, approve a Quote, or change Settings. A workspace with Full access can operate the Book and commercial workflows but cannot change billing, credentials, or ownership — those remain separately authorized.

What access does not grant

Access is not ownership. Access is not billing responsibility. Access is not a second workspace identity.
  • Access is not ownership. The connected Account owns its Book, environments, and history. Your workspace holds a connection — it does not own the Account.
  • Access is not billing responsibility. A workspace with Full access may or may not be the billing Account. Billing is set explicitly per connection. See Billing responsibility.
  • Access is not workspace switching. A connected Account is not a second directly operated workspace. It appears in the Accounts portfolio, not in Clerk’s OrganizationSwitcher. See Create or switch workspaces.
  • Access is not permanent. A connection can be revoked at any time. Revocation removes your workspace’s authority immediately. See Revoke a connection.

Rules and boundaries

  • A URL or Account ID never grants access. Every request is verified against the active Clerk Organization and an active connection.
  • A revoked or absent connection produces the same not-available result as a foreign or malformed Account ID. The interface never reveals whether an Account exists but is unavailable versus unreachable.
  • Clerk roles do not automatically grant connected Account access. An org:admin in the controller workspace still needs an active connection with sufficient access level to operate a connected Account.
  • A connected Account may also be independently operated through its own Clerk Organization. That adds direct access without duplicating the Account or changing its history.

Create an Account

Create a new third-party Account and choose its access level.

Connect an existing Account

Connect an existing Account and choose its access level.

Billing responsibility

Who pays for what when an Account is connected.

Revoke a connection

Safely remove access to a connected Account.