# Security

How Reviso protects agent connections, content, and account access — token scope, data access, audit, and how you revoke authorization.

## Agent connections and token scope

Agent connections are account-level. An authorized agent can only reach the team spaces and documents the underlying Reviso account can reach, and every MCP call passes the same capability checks the browser uses. A connection never silently grants administrative or other-account access.

- Transport: Streamable HTTP, scoped to the agent connection

- Auth: OAuth 2.1 / PKCE with browser consent

- Local tokens: For headless agents that cannot open a browser; scope equals the account that minted them

## Break-glass and account credentials

Owner and bootstrap keys are break-glass management paths only. They are not used to authorize content reads or writes by an account, and an owner key is not accepted as a substitute for a normal connection.

## Content access model

Reviso applies the same membership, shared-link, and permission model to agents and humans. Tool visibility is filtered by the capability map of the connection at call time, and every writing tool enforces its route capability independently.

- view — read documents, versions, and structure

- edit_file — propose structured edits and versions

- comment — create, reply, and resolve comment threads

- manage_members — create and revoke invites and share links

- archive_file — archive and restore documents

## Audit and provenance

Document edits carry provenance: version history, rollback, comments with anchor evidence, and collaborative-update CRDT rows are content truth. Failed intents are recorded and recoverable rather than silently overwritten.

- Versions: Every agent-authored update cuts a reviewable version

- Rollback: Revert to any prior version in the browser

- Failed writes: Recoverable intents; no silent data loss

## Revoking access

Revoke an agent connection or a local token at any time from Settings > Integrations. Revoking removes the saved grant; the client can no longer authenticate without a fresh OAuth consent.

## Reporting a vulnerability

Keep security feedback focused on the connection layer, content-access model, and capability enforcement. Report by contacting the maintainers directly before public disclosure.

[Reviso documentation](https://reviso.work/docs)
