Access, security and disconnecting
What an assistant can see, how long access lasts, and how to disconnect it.
An assistant connected to your account is, to Waypoint, you. This article explains what that means and how to take the access away again.
What it can see and do
- Only the teams and projects you can see, and only the actions your role allows.
- Every change appears in the activity feed with your name and sends the usual notifications, so your team can always tell what happened.
- It cannot reach your password, security settings or billing.
Approving a connection
The first time a client connects, Waypoint shows an authorization page naming the client and what it is asking for. Only approve clients you set up yourself. If a page like this appears when you were not connecting anything, choose Cancel.
How long access lasts
A connection stays signed in for up to 30 days of use. Clients renew it quietly in the background; if you have not used the assistant for a month, it asks you to sign in again. Signing out of Waypoint in your browser does not sign the assistant out.
Disconnecting
Remove Waypoint from the client: delete the connector in Claude or ChatGPT, remove the entry from Cursor's or VS Code's settings, or run claude mcp remove waypoint for Claude Code. The client forgets its sign-in and can no longer reach your account.
If a device with a connected assistant is lost or stolen, write to us straight away from the email address on your account and we will cut off its access immediately.
For team owners and admins
You cannot see or manage your teammates' assistant connections; each person manages their own. Because an assistant can only ever do what its owner can, removing a person from the team also removes what their assistant could reach.