Permissions

Exactly what Spillway can—and cannot—do.

Every capability is tenant-specific. Documentation, authentication, and provider availability are evidence inputs, never automatic authority.

Version permissions-surface-2026-08-v1. This surface describes the implemented product boundary.

What Spillway can read

Only after contractor authorization and tenant-specific verification, Spillway may read completed-call metadata and content, bounded ServiceTitan schedule and business records needed for Calls, provider connection health, and external evidence needed by the existing proof system.

What Spillway can write

A verified scheduling connection may create the bounded inspection appointment authorized by the contractor and homeowner decision. Every write requires the strongest available just-in-time schedule check and provider confirmation before Spillway represents the appointment as booked.

What Spillway can communicate

After tenant-specific messaging capabilities, registration compatibility, and every policy gate are verified, Spillway may send the approved continuation through the contractor's existing messaging provider. When that provider cannot safely satisfy the contract, a separately registered Spillway-managed Twilio sender may be used instead. Consent, contactability, quiet hours, suppression, STOP, START, HELP, terminal-state, and duplicate protections still apply to every message.

Billing and proof

Stripe may collect the $1 installation payment and, only after canonical qualifying proof authorizes it, execute the $299 monthly subscription. Stripe cannot create proof. ServiceTitan or another provider supplies evidence; the proof foundation decides whether that evidence satisfies the accepted condition.

What Spillway cannot do

Spillway cannot port or reroute the contractor's phone system, invent availability, claim a booking without provider confirmation, fabricate a signed job, use one contractor's sender or credentials for another, bypass suppression, or turn documented provider capability into verified tenant authority.

Authorization and revocation

The contractor confirms consequential business facts, accepts versioned commercial and communications terms, and authorizes each provider connection. Existing-number access, messaging scopes, registration use case, and staff visibility are verified independently. Connections can be revoked and messaging paused. Disconnecting Spillway from a contractor-owned provider does not destroy the contractor's number or inbox; bounded offboarding preserves required historical proof and financial records.