Skip to content

Revoking access

WhatWho can do itWhereTakes effect
An AI keyRentametrix staffAdmin, API keys & grants, the key’s Revoke button; confirm “Revoke MCP key”At once. Every request checks the key against the database; a revoked key fails on the next call. The key shows Revoked in the list.
One tool or property on a keyRentametrix staffManage grants on the key; remove the tool or propertyOn the next call. Grants are read fresh every time.
Browser sign-in for one person’s AI tool (connector access)Rentametrix staffOn requestWithin about a minute across servers. Tokens the person’s AI tool already holds live until they expire; ask us to revoke the authorized client in the login provider as well.
A person’s membershipan account admin or RentametrixAccount, Team members, Deactivate; or the user page, Remove from accountThe server refuses the person on every request once their token refreshes, at most one hour. Their property grants are ended with the membership. Their login still exists and can be reactivated.
One property from a personan account admin or Rentametrixthe user page, Property grants, Remove, Save changesAt the next token refresh, at most one hour; a fresh sign-in applies it at once
ResidentReadRentametrix staffOn request; audited with a reasonNext sign-in or token refresh
Data ReviewerRentametrix staffOn requestAt once for the Review inbox; the server re-checks the role on every review request
A global roleRentametrix staffOn request; audited with a reasonAt the next token refresh, at most one hour
  • A revoked key gets an authentication error from every endpoint, including the AI tool endpoint. There is no grace period.
  • A deactivated user who is still signed in keeps a token for up to an hour, but every property check refuses an inactive user on the server, so lenses, exports and chat return nothing.
  • Nothing a key or user wrote is rolled back by revocation. Keys reach reads and exports only; no key can write through the AI surface.
  1. Revoke it in API keys & grants (or ask Rentametrix to). Do not wait to find out where it went.
  2. Mint a new key with the same grants and give it to the tool that needs it. The full key shows once at minting; copy it into a secret store before closing the sheet.
  3. Ask support for the key’s call log if you need to know what it read. Each call is logged with the key id, the tool and its side-effect class. There is no customer-visible audit log in the app yet.
  1. Deactivate the membership.
  2. Revoke any key minted for their personal AI tool, and connector access if they had it.
  3. If they held ResidentRead or Data Reviewer, ask Rentametrix to revoke those too; deactivation ends the membership, not those flags.