Trust & Data · Permissions
What is the worst Spillway could actually do with the access I give it?
The maximum authority Spillway gets.
What every connection technically allows, what Spillway actually uses, what could go wrong, and how you shut it off.
Spillway connects to real business systems. That creates real authority.
We think you should be able to inspect the maximum authority behind every connection before granting it.
This page separates what the provider technically allows from what Spillway actually uses.
If a provider gives Spillway broader technical access than the product uses, we say that too.
What are you actually risking?
The $299 activation payment is not the only thing at risk when you connect software to your business.
Your calls, recordings, messages, business identity, payment method, and customer relationships matter more than the dollar.
Do not ask only: “What does Spillway intend to do?”
Also ask: “What does the access I’m granting technically make possible?”
That is what this page answers.
Four boundaries, not one permission claim.
These concepts are different. Each connection below states all four.
Provider-granted authority
What the provider credential, OAuth grant, API key, or authorization technically permits. This is the ceiling.
Spillway-used authority
What Spillway actually uses that authorization to do. This can be narrower than the provider ceiling.
Spillway-enforced restrictions
What Spillway’s application prevents itself from doing even when the provider authorization is broader.
Worst-case authority
What could plausibly happen if the authorization were misused, a control failed, or an authorized credential were compromised.
Connection
Call history.
Spillway uses authorized completed-call information to find legitimate roofing conversations that ended without an inspection.
Why Spillway needs it
The original call is the evidence for what happened, whether the call is eligible, and what follow-up would be truthful.
What Spillway can change
This connection is used for authorized call reads and event intake. It does not authorize changes to the contractor’s CRM or schedule.
What Spillway actually uses
- Completed-call identity, timing, direction, participants, and duration.
- Recording or transcript when the provider account exposes it.
- Available recent completed-call history when the provider supports it.
- New completed-call events after service starts.
Provider-granted authority
The OAuth grant or provider credential may expose more calls, recordings, numbers, or account resources than a single recovery requires. The provider’s grant screen is the technical ceiling.
Spillway-used authority
Spillway limits normal use to eligible-call analysis, recovery continuity, reconciliation, and provider-health checks.
Spillway-enforced restrictions
- Tenant-bound provider account.
- No homeowner message before service starts.
- Eligibility and contactability checks before any continuation.
- No cross-tenant provider identifiers.
- No generated success from missing call evidence.
Worst case if this access were misused
If this authorization were compromised, the call records, phone numbers, recordings, or transcripts exposed by the grant could be read until the authorization was revoked.
What reduces that risk
- Pipedream Connect tenant binding.
- Server-side token custody.
- Signed and replay-controlled event intake where available.
- Redacted operational logs.
- Revocation and fail-closed capability state.
How you shut it off
- Disconnect the provider in Spillway.
- Revoke the connected account through the provider or Pipedream Connect.
- New call ingestion and dependent recovery stop after revocation is confirmed.
View technical permissions →
The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.
- Connection broker
- Pipedream Connect with a Spillway-owned project and server-issued, short-lived connect token.
- Authorization method
- Provider-specific OAuth or credential form presented by Pipedream Connect.
- Authorized resources
- Only the resources exposed by the provider grant accepted for the selected account.
- Read operations
- Provider-specific completed-call, recording, transcript, number, and reconciliation reads after capability verification.
- Write operations
- None through the call-history role.
- Events
- Provider-specific call events or bounded reconciliation reads.
- Tenant binding
- The authorization is bound server-side to one contractor account and setup session.
- Credential storage
- Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
- Auditability
- Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
- Revocation
- Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
- Failure behavior
- Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
- Last reviewed
- August 24, 2026. The actual account capabilities are checked again after authorization.
Connection
Customer messaging.
After service starts, Spillway uses an authorized business-messaging route to continue the unfinished homeowner conversation.
Why Spillway needs it
The recovery conversation must use an authorized sender, receive replies, observe delivery, and honor opt-outs.
What Spillway can change
This authority can create outbound messages through the selected sender and receive messaging events. It cannot edit the contractor’s CRM or schedule.
What Spillway actually uses
- Select an authorized business number.
- Send recovery messages only after service starts and readiness checks pass.
- Receive homeowner replies and delivery events.
- Recognize human participation and enforce opt-out or suppression state.
Provider-granted authority
The messaging authorization can expose the numbers, conversations, messages, and send operations allowed by the provider grant. Some grants may be broader than Spillway’s normal use.
Spillway-used authority
Spillway uses the selected sender only for tenant-bound eligible recovery situations and the office-confirmed inspection exchange.
Spillway-enforced restrictions
- No homeowner message before the authorized connection is ready and the $299 activation payment succeeds.
- Exact tenant, provider, and sender binding.
- Messaging registration and entitlement checks.
- STOP, START, HELP, quiet-hours, suppression, and duplicate-message controls.
- Release authority defaults closed.
Worst case if this access were misused
If messaging authority were compromised or its controls failed, an unauthorized message could be sent through the contractor’s approved business identity, creating customer, brand, carrier, and regulatory harm.
What reduces that risk
- Provider capability verification.
- Tenant and selected-number binding.
- Production release controls.
- Idempotent dispatch.
- Inbound signature and replay checks where available.
- Delivery reconciliation.
- Immediate opt-out suppression.
How you shut it off
- Pause messaging for the tenant.
- Disconnect the messaging provider.
- Revoke the account through the provider or Pipedream Connect.
- Existing delivery events may still arrive for messages accepted before shutdown.
View technical permissions →
The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.
- Connection broker
- Pipedream Connect; a separate supported messaging provider can be connected when the call provider does not supply messaging.
- Authorization method
- Provider-specific OAuth or credential form.
- Read operations
- Selected-number inventory, supported message thread or event reads, replies, opt-out state, and delivery evidence.
- Write operations
- Create approved SMS messages through the selected authorized sender.
- Events
- Inbound message and delivery-status events, or documented reconciliation where the provider requires it.
- Tenant binding
- The authorization is bound server-side to one contractor account and setup session.
- Credential storage
- Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
- Auditability
- Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
- Revocation
- Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
- Failure behavior
- Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
- Last reviewed
- August 24, 2026. The actual account capabilities are checked again after authorization.
Connection
Office email handoff.
Spillway emails the contractor’s verified work address when homeowner availability requires office times and when a time is confirmed.
Why Spillway needs it
The office remains the authority for its real schedule without granting Spillway access to a CRM or calendar.
What Spillway can change
Email delivery can notify and request a response. It cannot create or change an appointment in the contractor’s system.
What Spillway actually uses
- Use the operational email associated with the contractor’s invitation or recovery session.
- Request a small set of real available inspection times.
- Send the final homeowner-confirmed time and context for the office to schedule.
- Send connection and billing notices required by the service.
Provider-granted authority
Spillway’s transactional email provider can send approved transactional messages from the configured Spillway sender to verified service recipients.
Spillway-used authority
No newsletter or marketing list is created from setup email authority.
Spillway-enforced restrictions
- Verified setup identity.
- Transactional templates only.
- No homeowner content in analytics event names.
- Expiring and session-bound verification codes.
- Rate and attempt limits.
Worst case if this access were misused
If this authority were misused, incorrect or excessive transactional email could be sent from Spillway’s domain.
What reduces that risk
- Resend credential custody.
- Verified sender domain.
- Template and recipient validation.
- Rate limiting.
- Redacted error logs.
How you shut it off
- Disable transactional email delivery.
- Rotate or revoke the Resend credential.
- Contact Spillway to change or remove the office recipient.
View technical permissions →
The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.
- Provider
- Resend transactional email.
- Read operations
- Delivery status required for support and reliability.
- Write operations
- Send approved transactional email templates.
- Tenant binding
- The authorization is bound server-side to one contractor account and setup session.
- Credential storage
- Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
- Auditability
- Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
- Revocation
- Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
- Failure behavior
- Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
- Last reviewed
- August 24, 2026. The actual account capabilities are checked again after authorization.
Connection
Starting payment and subscription.
Stripe collects the $299 activation payment when service can begin and keeps the approved payment method for later recurring charges.
Why Spillway needs it
The $299 activation and later recovery-anchored recurring charges must be verified server-side and processed without Spillway storing raw card details.
What Spillway can change
The billing service can create authorized payment and subscription objects in Spillway’s Stripe account. It cannot affect calls or messages.
What Spillway actually uses
- Collect exactly one $299 activation payment when service can begin.
- Store a reusable Stripe payment-method reference under the accepted terms.
- Record the first qualifying confirmed recovered inspection as a $0 recurring-billing anchor.
- Charge the next $299 exactly 30 days after that recovery, then every 30 days.
- Receive signed payment, subscription, refund, and dispute events.
Provider-granted authority
Stripe authority can create charges and subscriptions against saved payment methods within Spillway’s merchant account. Misuse could create an unauthorized charge.
Spillway-used authority
Spillway permits the $299 activation after an exact provider connection and permits recurring billing only from the first authoritative qualifying confirmed-recovery timestamp.
Spillway-enforced restrictions
- Raw card details stay with Stripe.
- Browser redirects never establish payment truth.
- Signed webhook verification and event deduplication.
- No recovered inspection means no second $299 charge.
- The first recovery creates no charge and anchors the next $299 exactly 30 days later.
- Ten elapsed days never manufacture billing authority.
- Disputed, paused, or offboarded state blocks the transition.
Worst case if this access were misused
If payment authority were compromised or the billing controls failed, a saved payment method could be charged outside the accepted product rule.
What reduces that risk
- Stripe-hosted payment fields.
- Signed webhook authority.
- Idempotency.
- Tenant-bound billing state.
- Release kill switch.
- Audit records and dispute handling.
How you shut it off
- Pause or cancel the subscription.
- Remove or replace the payment method through the supported billing path.
- Disable monthly-billing release authority.
- Raise a disputed charge with Spillway and the card issuer.
View technical permissions →
The provider’s authorization is the technical ceiling. Spillway’s application behavior may be narrower.
- Provider
- Stripe.
- Authorization method
- Stripe-owned payment fields or Stripe-hosted checkout and authenticated Stripe webhooks.
- Read operations
- Payment, payment-method reference, subscription, invoice, refund, and dispute state.
- Write operations
- One $299 activation payment and the later recovery-anchored $299 recurring subscription.
- Webhook authority
- Only signature-verified, replay-safe Stripe events advance payment state.
- Tenant binding
- The authorization is bound server-side to one contractor account and setup session.
- Credential storage
- Provider credentials remain server-side and are not returned to the browser, analytics, or public logs.
- Auditability
- Relevant authorization, provider, messaging, activation, and billing events use tenant-bound operational records.
- Revocation
- Disconnect through Spillway and revoke directly through the provider when the provider offers that control.
- Failure behavior
- Expired, revoked, or incomplete authority stops dependent action; it does not become a fabricated success.
- Last reviewed
- August 24, 2026. The actual account capabilities are checked again after authorization.
