{"scopes":[{"name":"read","label":"Draft-only","can":["Create and edit draft posts","Schedule drafts for future publishing","Submit drafts for review","Upload media","Generate images and video","Read analytics, best times, listening hits, CRM contacts","Export reports"],"cannot":["Publish posts","Approve posts","Manage API keys","Manage report branding"]},{"name":"write","label":"Full access","can":["Everything in read","Publish posts (still blocked by the approval guardrail when the brand requires approval)","Submit posts for review"],"cannot":["Approve posts","Manage API keys","Manage report branding"]},{"name":"admin","label":"Administrator","can":["Everything in write","Approve posts in review","Create and revoke API keys","Manage white-label report branding"],"cannot":[]}],"approval_guardrail":"Brands may require approval before publishing (brands.require_approval_before_publish). Lifecycle: draft → in_review → approved → published. A connector must NEVER bypass human review: publish calls on unapproved posts fail, and draft-only (read) keys cannot publish or approve at all — enforced identically in the REST API and the MCP tools."}