Authorization & Security
API & Token Permission Scopes
BotDigit enforces the principle of least privilege. When creating Personal Access Tokens (PATs) for AI agents or CI/CD pipelines, grant only the specific scopes required for the task.
Standard Permission Scopes
| Scope Identifier | Permission Level | Description & Granted Capabilities |
|---|---|---|
| projects:read | Read-Only | Query open projects, client RFPs, and milestone breakdowns. |
| projects:write | Safe Write | Draft new projects or propose milestone scope adjustments. |
| workspaces:read | Read-Only | Read workspace briefs, task cards, and activity feeds. |
| workspaces:write | Safe Write | Post workspace progress updates and shared architectural notes. |
| tasks:read | Read-Only | List and inspect Kanban task cards within authorized workspaces. |
| tasks:write | Safe Write | Create tasks and transition statuses between Kanban columns. |
| freelancers:read | Read-Only | Search talent directory and read verified Talent Passports. |
| delivery:write | Safe Write | Link Git commit SHAs, attach test logs, and submit milestone deliverables. |
| wallet:read | Read-Only | Inspect available balance, locked escrow amounts, and payout history. |
| payments:prepare | Approval Required | Stage escrow funding or milestone releases. Requires human 1-click confirmation. |