Guides·Real-estate media

What access should you give an automation that places orders in Aryeo?

The least that does the job: a team-member login on Aryeo — never the owner login — and read access to the one mailbox the order emails land in, with permission to label messages. It should run in your own Google and GitHub accounts, so you can see what it does, switch it off in minutes, and keep the code if the person who built it is unavailable.

Anton Osipov · Updated September 24, 2026

What it actually needs

Order entry touches two things: the email that holds the order and the form that creates it. The access should match that and stop there.

  • Aryeo: a team-member account with permission to create orders and see the schedule. It enters orders the way your admin does.
  • Email: read access to the mailbox the concierge or order emails arrive in, plus permission to add labels, so a placed or kicked-out order is marked where your team already looks.
  • Nothing else: no owner settings, no payment methods, no access to other mailboxes.

What it should never have

Owners are right to notice every login. These are the lines worth holding.

  • The owner login. If it is shared, it cannot be told apart from you, and it cannot be revoked without changing your own password.
  • The ability to charge a customer. Concierge orders are invoiced later; the order should be submitted with no payment step at all.
  • Credentials sent by email or pasted into code. Logins belong in a secrets store in your own cloud account.
  • Access to everything “just in case”. Every extra permission is something to audit later.

Where it runs and who holds the keys

This is the technical part, and the part that answers the question owners ask about key-person risk. Our modules run in the client’s own Google and GitHub accounts, and the client keeps the code. Whoever builds yours, ask for the same:

  • The code in a GitHub repository in your organisation, yours whether or not you keep working with the builder.
  • The scheduled job in your own Google account, so the bill, the logs and the off switch are yours.
  • Mailbox access granted through Google’s own consent screen, where your Google Workspace admin can see it and remove it.
  • The Aryeo login kept as a secret in your cloud account, not in the code and not in anyone’s inbox.
  • Every order logged as placed, verified or kicked out, so you can see what it did on any given day.

How to switch it off in five minutes

Being able to revoke access quickly is what makes it safe to grant. Remove the team member in Aryeo, remove the app’s mailbox access in your Google admin, and pause the scheduled job in your cloud project. Orders then arrive by email exactly as before, and your team enters them by hand until you switch it back on.

Questions people ask

Does it see customers’ payment details?

It should not need to. Order entry for concierge orders has no payment step, so the team-member role can be one without access to payments.

Why not use an API key instead of a login?

Aryeo does document an API that can create orders. Our modules use the order form today because the form carries each office’s rules; the API route is covered in its own guide.

What happens if the person who built it is unavailable?

It keeps running in your accounts, and the code and logs are yours. Any developer you choose can read the repository and take over.

Can I see what it did yesterday?

Yes. Every order it handled is logged with its outcome — placed, verified or kicked out with a reason — and each email carries a label showing the same.