Request-time access checks
Authenticated product and docs-context requests resolve the live user, workspace membership, agency grants, staff assignments, location permissions, and revocation state. A cookie or requested ID names a candidate context; it does not convey authority by itself.
Secret boundaries
Connection status reads credential-presence bits and health signals without selecting OAuth tokens. Personalized docs receive an allowlisted response and are never sent provider credentials, API keys, member identities, or individual transaction data.
Source honesty
Adsu distinguishes no data from zero, liveness from authorization, and real browser beacons from bots or synthesized events. When a source cannot support a current claim, the product can show blank, Awaiting, Idle, Reconnect, or Expired instead of carrying a false-green state.
Mindbody handling
Mindbody-derived data uses a conservative rolling refresh posture. During a source blackout or disconnect, affected surfaces can fail empty and repopulate after a successful reconnect rather than retaining stale provider-derived claims indefinitely.
Report a concern
If you believe an account, location, or provider connection is visible to the wrong person, stop sharing the affected session, revoke the relevant access in Adsu, and contact Adsu support with the workspace and location names—never with raw credentials.