Back to blog
Field notes4 min read

A credential that can write does not get in.

Read-only is not a checkbox on a vendor form. On ConnectWise we prove it with a write that must fail. On Halo we refuse to try, because the try would create a client.

Kevin Townsend

September 1, 2026

A key that can change a customer record is not a read-only key. We do not store it. We do not pull against it.

That is the whole rule. What changes is how you prove it, because not every PSA will let you ask the question safely.

An MSP does not hand you their book because they liked a slide. They hand you a credential. That credential has whatever rights the last person who set up the API member left on. Sometimes that is inquire-only. Sometimes it is inquire plus add plus edit, because an integration asked for it a year ago and nobody took it back.

If we connect through a key that can write, we have accepted the ability to mutate their companies, their tickets, their invoices. Calling that read-only because a setup form said so is a comment. We will not run a client book on a comment.

The obvious move is to trust the vendor's scope string. If nothing says write, call it safe. That is how a role named something like "Customers Read Write" gets certified, because the word read appears in it.

Scope strings lie. Rights live on the member.

On ConnectWise we do not argue with the string. We try a write that is built to change nothing useful, and we listen to the answer. If the PSA refuses the write, the key can come in. If the PSA accepts the write, the key does not. If the answer is a shrug, empty module, noise, we fail closed. Unproven is not proven.

That probe is not a health check. It is the gate. It runs before any read.

Halo will not give us that conversation. The write that would prove the point creates or updates a real client. So we do not try. There is no probe. Data calls are reads. If the credentials we were handed already ask for write, we stop before we talk to Halo at all.

Do not read that as Halo being further along. It is not. ConnectWise and NinjaOne are live: whole book, read-only, proven against a real tenant. HaloPSA is pilot: one client to start. HubSpot is next: designed, not connectable today. Pilot is not a softer live.

The free look, Client 360, is that same promise. Read-only. Nothing writes back. What we do after you have seen the book is a separate conversation, not a connect-time surprise.

If you are the person who will mint the member, make it boring. Inquire. No add. No edit. The boring outcome is the point.

A credential that can write does not get in. We will keep saying it. The proof will keep changing shape when the vendor does. The rule will not.

From the build

Want this kind of operator math on your business?

Catalyst OS is the business-layer operating system for an MSP — your CRM, PSA, and RMM finally talking to itself, with the next move already made.

See your book — freeBook a 30-minute listen