AI Assistant (Leat MCP)
July 20
→
Access control & audit logs
Know who changed what, when, and from what value. Record every configuration change and every manual action on a customer, with the actor, the timestamp, and the state before and after. Because the log can't be edited by anyone, including administrators, what it says is what happened.
Assign roles for program owners, marketers, finance teams, regional managers, store managers, and counter staff. Set separate permissions for viewing, creating, editing, approving, and publishing. A marketer can prepare a campaign that requires approval before publication, while finance can review budgets without changing rewards. Built-in roles can be adjusted, or new roles can be created around your organization.
Control which parts of the business each person can see and manage. A store manager can be limited to one location, a regional manager to their region, and a franchisee to their own sites. Teams operating several brands can keep each group within the relevant program. These scopes also determine which customer details, purchase history, and custom attributes each role can access.
Counter staff can identify customers, award value, and redeem rewards without seeing budgets, program rules, campaign settings, or unnecessary customer data. Individual logins connect every action to the person who took it and can be deactivated when someone leaves. Connected systems receive separate credentials with their own permissions, allowing one key to be rotated or revoked without affecting other integrations.
Leat logs changes to rules, budgets, rewards, campaigns, thresholds, roles, and integrations. Manual customer actions are also recorded, including balance adjustments, profile merges, account flags, consent changes, and erasure requests. Approvals and declined changes appear in the same history. Each entry records who acted, when, what changed, and the state before and after, creating a record that cannot be edited by users or administrators.
Role design & definition
Responsibilities can be divided between program owners, marketing, finance, regional teams, and store staff without giving everyone full access.
Location and branch access
Each user sees and manages only the stores, regions, or branches within their responsibility.
Staff onboarding & offboarding
Individual access can be issued when someone joins and removed when they leave without affecting other employees.
Integration credential management
Each connected system can use its own limited credentials, which can be rotated or revoked independently.
Customer data access control
Sensitive customer details remain available only to roles that need them, while counter staff see only what the transaction requires.
Charge investigations
Teams can trace configuration changes and manual customer actions to the responsible person, with the previous and updated values preserved.







































