Connecting Claude to Elevate safely: permissions, a spend cap and an activity log
Your own AI assistant can work in Elevate. Here is how to connect it, what each permission allows, and how you see and undo what it did.
The Elevate team
2 min read
Your AI assistant
Activity in ElevateCap $25.00 a month
- Find contactJessica Turner, uses Read
- Add to listSpring buyers, uses Create and edit
- Send emailTo Jessica Turner, uses SendRefused: needs Send
If you already use an AI assistant like Claude, you can let it work in Elevate: find contacts, build a list, draft a follow-up, check on a campaign. It connects through MCP (the Model Context Protocol), an open standard that lets an assistant use another app's tools. Any MCP client that connects over HTTP works the same way. ChatGPT's custom connectors use the same standard; we're testing that now, so it's marked coming soon.
Letting an AI touch your CRM should make you a little nervous. That's healthy. Here is what keeps it safe.
Connect it
In Claude, add a custom connector with Elevate's address:
https://app.elevatelistings.ai/api/mcpOr in Claude Code, run:
claude mcp add --transport http elevate https://app.elevatelistings.ai/api/mcpThen sign in with your Elevate account. You're never asked to paste a password into the assistant. Tick what it may do, set its monthly spend cap, and allow it.
Tools that can't sign in this way can use a personal access token instead, with the same choices and an expiry date you pick.
It can only do what you can do
A connection runs as you, with your role. It sees what you can see in Elevate and nothing more, and permissions only ever narrow that. They never add power.
You choose what it may do
| Permission | What it allows |
|---|---|
| Read | Look at listings, contacts, campaigns and reports. Always on. |
| Create and edit | Add and change contacts, tasks, pages and workflows |
| Send | Email on your behalf (texts once texting turns on) |
| Publish | Put pages and brochures live |
| Delete | Remove things. Every delete can be restored. |
| Spend | Paid AI and data, up to the cap |
Billing and admin permissions exist too, for company admins, and are off unless you tick them.
A good start is Read plus Create and edit. Let it draft; you send. Add Send once you trust what it writes.
It has its own spend cap
Each connection has a monthly spending cap, $25 unless you change it, separate from your company's usage budget. Paid work it runs, like an AI draft or a home lookup, is billed like anywhere else in Elevate, at our cost plus 10%, and counts toward that cap. Past the cap, paid work is refused.
A big paid batch never just runs. If it asks to look up a few hundred homes, it first shows you the count and the cost, and waits for your yes.
Everything it does is in its activity log
Every call it makes is logged with the time, what it did and what it cost. That includes the refusals: if it tries to send an email without the Send permission, the log shows "Refused: needs Send", and nothing is sent.
If it deletes something it shouldn't have, restore it from the log.
Revoke it at once
Change a connection's permissions or remove it in Settings, under Connected apps. Removing access works immediately.
The safest assistant is one whose every move you can see and undo. That's the bar we built to.