Exact definitions
How access levels relate
Access levels are cumulative. Each higher level includes everything the lower levels permit:What access does not grant
- Access is not ownership. The connected Account owns its Book, environments, and history. Your workspace holds a connection — it does not own the Account.
- Access is not billing responsibility. A workspace with Full access may or may not be the billing Account. Billing is set explicitly per connection. See Billing responsibility.
- Access is not workspace switching. A connected Account is not a second directly operated workspace. It appears in the Accounts portfolio, not in Clerk’s OrganizationSwitcher. See Create or switch workspaces.
- Access is not permanent. A connection can be revoked at any time. Revocation removes your workspace’s authority immediately. See Revoke a connection.
Rules and boundaries
- A URL or Account ID never grants access. Every request is verified against the active Clerk Organization and an active connection.
- A revoked or absent connection produces the same not-available result as a foreign or malformed Account ID. The interface never reveals whether an Account exists but is unavailable versus unreachable.
- Clerk roles do not automatically grant connected Account access. An
org:adminin the controller workspace still needs an active connection with sufficient access level to operate a connected Account. - A connected Account may also be independently operated through its own Clerk Organization. That adds direct access without duplicating the Account or changing its history.
Related tasks
Create an Account
Create a new third-party Account and choose its access level.
Connect an existing Account
Connect an existing Account and choose its access level.
Billing responsibility
Who pays for what when an Account is connected.
Revoke a connection
Safely remove access to a connected Account.