Connect
Connections are the accounts your agent works with. Each one is a single OAuth click from Dashboard → Connect; you approve the scopes on the provider’s own consent screen, and the token goes straight into Waveguide’s encrypted vault. The AI model never sees your credentials — see Security for how that’s enforced.
Connections belong to the active workspace only. They do not carry over when you switch workspaces. Use a separate workspace (and reconnect there) for personal vs business Gmail, social, or other accounts.
You can connect as little as one account to start. Starter plans include up to 3 connections; Growth and Scale are unlimited.
Outreach email (hosted)
Job outreach does not require Gmail. Waveguide auto-provisions a dedicated sending address
(hello@your-slug.mail.waveguide.email) with warm-up caps, CAN-SPAM footer, and one-click unsubscribe.
Prospect replies are forwarded to you and also wake the agent. Optionally add your own brand domain under
Dashboard → Capabilities.
Gmail
What the agent does with it: reads incoming mail relevant to the growth loop (lead replies, platform notifications), drafts and optionally sends as you, and watches for new-lead signals in real time via push notifications. Job 1:1 outreach defaults to the hosted Waveguide address above.
Autonomy: reading is free (T0) and drafting is logged (T1). Sending is a T2 action — it requires approval until you create a standing policy like “auto-approve first replies to new leads.”
Google Calendar
What the agent does with it: reads your availability to propose booking slots to leads, and watches for changes (a booked call is a strong conversion signal worth recording in the ledger). Powers the Waveguide native booker when scheduling mode is Waveguide under About my business.
Autonomy: read-only by default (T0). Creating events is T2. Public booking-page creates use a narrow standing
policy (marker public_booking) so visitors can book without a human click each time.
Calendly
What the agent does with it: lists your event types and books invitees when scheduling mode is Calendly. Connect from Dashboard → Connect, then pick the event type on About my business.
Autonomy: reading event types / availability is T0. Creating invitees is T2. Webhooks
(invitee.created / invitee.canceled) sync leads and cancel local bookings when Calendly’s plan allows
subscriptions; otherwise use Sync under scheduling APIs. Booking modes are set on
About my business.
Meta Ads
What the agent does with it: reads campaign/ad-set/ad performance, receives lead-form webhooks instantly, proposes and executes budget changes and pause/scale decisions, and launches creative variants.
Autonomy: reads are free (T0). Budget changes and campaign launches are T2 and always respect your hard daily spend cap — which defaults to $0 until you raise it. The cap is enforced in the proxy, not in the prompt.
Stripe
What the agent does with it: reads payment events so revenue is attributed back to campaigns and leads in the ledger — and works the collect side of your money: chases overdue invoices, retries failed payments, sends payment links, pauses (instead of losing) subscriptions, and drafts chargeback dispute responses.
Autonomy: reads are free (T0). Collect-side actions — sending an invoice, a payment link, a dunning retry, a dispute response — are T2: they ask first until you set a standing policy. Anything that moves money out of your account (refunds, credits) is T3 and always requires your explicit approval, every time. Waveguide never initiates transfers, payouts, or purchases from your Stripe account — those paths aren’t even reachable through the proxy.
Social (X, Instagram, LinkedIn, Facebook, TikTok)
What the agent does with it: drafts and publishes posts, sends DMs where the network supports it, and reads comments/engagement. You connect each network from Dashboard → Connect → Social — Waveguide opens the network’s own linking page (via our social backend). You never paste an API key.
Autonomy: reading accounts and comments is free (T0). Posting and DMs are T2 — they require approval until
you create a standing policy. Platform names in tool args use Ayrshare’s ids (twitter for X, instagram,
linkedin, etc.).
Meta Ads (above) is separate: that connection is for paid ads, not organic posting.
Slack / Telegram
Chat channels are where the agent reports and asks for approval — not accounts it operates. Connect them from Dashboard → Connect (Channels section), or under Settings → Channels. See Channels for details.
Managing connections
- Status for every connection is on the Connect page: active, expired, or revoked.
- Disconnecting removes the credential from the vault immediately. In-flight sessions lose access at the proxy on the next call.
- If a provider expires a token, the agent flags it in your brief and the dashboard shows a reconnect prompt.
What the agent can never do
Regardless of connections, the proxy enforces hard rules: no action outside your granted scopes, no spend above your daily cap, no T2/T3 action without approval or a standing policy, and no calls to providers you haven’t connected.