| An AI key | Rentametrix staff | Admin, API keys & grants, the key’s Revoke button; confirm “Revoke MCP key” | At once. Every request checks the key against the database; a revoked key fails on the next call. The key shows Revoked in the list. |
| One tool or property on a key | Rentametrix staff | Manage grants on the key; remove the tool or property | On the next call. Grants are read fresh every time. |
| Browser sign-in for one person’s AI tool (connector access) | Rentametrix staff | On request | Within about a minute across servers. Tokens the person’s AI tool already holds live until they expire; ask us to revoke the authorized client in the login provider as well. |
| A person’s membership | an account admin or Rentametrix | Account, Team members, Deactivate; or the user page, Remove from account | The server refuses the person on every request once their token refreshes, at most one hour. Their property grants are ended with the membership. Their login still exists and can be reactivated. |
| One property from a person | an account admin or Rentametrix | the user page, Property grants, Remove, Save changes | At the next token refresh, at most one hour; a fresh sign-in applies it at once |
| ResidentRead | Rentametrix staff | On request; audited with a reason | Next sign-in or token refresh |
| Data Reviewer | Rentametrix staff | On request | At once for the Review inbox; the server re-checks the role on every review request |
| A global role | Rentametrix staff | On request; audited with a reason | At the next token refresh, at most one hour |