Skip to content

Security and permissions

Access, AI and spend, each with a rule.

These are the controls that decide who can see a record, what the AI is allowed to change, and who can authorise recurring spend. They are described plainly, because a security page is only useful if it says exactly what happens.

If you need current security documentation for a procurement review, ask us. We will provide what exists rather than a badge.

Boundaries are stated

A view says whose eyes it is for, rather than implying it.

Access is reviewable

Who changed what, and when, stays inspectable.

No silent widening

Adding a product does not quietly expose another product's records.

How Magic controls access, AI and spend

What you can check for yourself

These are the checks an administrator can make inside the workspace, without asking us.

1 · Who is in the workspace

The people, their roles and the products they can reach.

  • The active users and their roles
  • Which products each role can open
  • The billing administrator and who can authorise spend

2 · Who can see a record

The permission that produced the view, not just the view itself.

  • The role label shown on a shared or guest view
  • The product badge on a panel from another product
  • The denial message when access is refused

3 · What is connected

The organisations and scopes you have actually granted.

  • The accounting organisation Magic reads
  • The mapping from the chart of accounts into plan lines
  • The authenticated connection settings for the other services

4 · What the AI has done

Every machine-assisted change is attributable.

  • The source shown with a suggestion
  • The person who approved it
  • The record of what changed and when

Security questions

See the controls before you commit

Read how connections work, or ask for the current security documentation behind these claims.