Best GEO Software
All posts
By Best GEO Software Teamtools

AI Visibility Platform Access Control: SSO, Team Roles, and Scoped API Keys

Seats, SSO gates, and API key scoping across AI visibility platforms: the access-control checklist buyers skip until the security review.

Access control is the part of an AI visibility purchase nobody evaluates until the security review blocks the rollout. By then you have already picked a tool for its dashboards and discovered that the seat count, the SSO gate, or the API key model does not fit how your team actually works. It is cheaper to check first. Here is the checklist, with the sourced facts we have for the tools we cover, and the reasoning behind each line.

Seats: count the humans first

Seat allowances vary more than any other plan dimension in this category, which is why it is the first thing to model. Promptwatch gives 1 seat on the free Explore tier and on Essential at $95/mo, 2 on Professional at $245/mo, 5 on Business at $579/mo, and 10 on every agency plan from Kick-off at $199/mo up. Peec AI, from $95/mo, takes the opposite approach with unlimited seats on every plan, which its reviewers consistently praise and which genuinely matters for large marketing teams where a dozen people want dashboard access without a procurement conversation.

The right reading depends on your shape, and the two products are not wrong for different shapes. Two analysts and a Looker report for everyone else fits Promptwatch's Professional fine, because the reporting layer, not the platform login, is where most stakeholders should live anyway. A stakeholder who reads a refreshed dashboard does not need a seat, and a seat they do not need is a cost you do not have to carry. Twelve hands-on users on a budget points toward Peec, with the coverage caveats our review documents, because unlimited seats from $95/mo is the answer to that specific shape and Promptwatch's seat math is not.

The mistake is to buy on seat count alone and ignore what the seats are for. A platform seat can change the program. A report reader cannot. Most of the people who want a login actually want the numbers, and a read-only report gives them the numbers without the seat.

SSO: enterprise-gated everywhere that publishes it

If your company mandates single sign-on for tools touching company data, budget for an enterprise tier before you pilot anything. Promptwatch lists SSO under Enterprise and custom pricing, alongside white-label and dedicated support. We have not found a tool in our coverage that publishes SSO on a self-serve plan, and any vendor that gates SSO also gates the price, so get the number in writing before the pilot rather than after. A pilot that lands on an enterprise price you did not budget for is a pilot that wasted a month.

Worth noting what does not need SSO to be safe, because not every integration is an SSO question. The OAuth connections a platform makes outward are a separate review. Promptwatch's Search Console connection is read-only OAuth, and its Slack agent installs via an org-owner grant, which means the workspace owner has to approve the install and the platform never holds Slack credentials. Those scopes are worth reading during the security review, and read-only outward connections are usually an easy pass. OpenAI's Publishers and Developers FAQ is a separate review item if ChatGPT Search crawl access is in scope. That is a robots and OAI-SearchBot question, not an SSO question, and conflating the two is how a security review gets stuck on the wrong thread.

API keys: scope is the whole game

This is the sleeper issue in the category. Visibility platforms now feed Looker reports, MCP chat sessions in Claude or Cursor, and custom scripts, and every one of those is a place a key can leak. A key on a laptop, a key in a shared report, a key pasted into a chat session, all of them are exposure surfaces, and the exposure is only as bad as the key's permissions.

What you want from the vendor is two things. Keys scoped by project versus organization, so a key for client A cannot read client B. And a read-only mode that actually removes write capability at the API surface, rather than politely suggesting it in the UI while leaving the write endpoints open.

Promptwatch has both, and one detail we like. On its MCP server, a read-only key hides the write tools entirely, so a chat session literally cannot bulk-create prompts or push a CMS draft. The write surface is gone, not hidden behind a button. The sane policy that enables is simple to state and harder to hold to: read-only keys everywhere a key sits on a laptop or in a shared report, one write-capable key on the single seat that publishes to the CMS, rotated when that person leaves. The full recipe is in read-only keys for Looker and MCP.

For the other trackers we cover, API access and key scoping are not documented at this level in our data, which is itself information. If the vendor's docs do not say how keys are scoped, the security review will ask, and "we'll check" burns a week of calendar time you probably did not budget. We treat the absence of published scoping as a question to ask in the pilot, not as a disqualifier, but it is a question.

The five-minute version

Count the humans who need the platform versus the humans who need a report, and pay for the first group only. Get SSO pricing in writing if you need it, before the pilot rather than after. Demand project-scoped read-only keys for anything that leaves the building, because a key that leaves the building is a key that will eventually leak. Then go back to comparing dashboards, which is the part of the evaluation most buyers actually enjoy. Full comparisons: directory, method: how we rank.

FAQ

How many seats does Promptwatch include?

1 seat on Explore and Essential at $95/mo, 2 on Professional at $245/mo, 5 on Business at $579/mo, and 10 on every agency plan from Kick-off at $199/mo. Peec AI lists unlimited seats on every plan from $95/mo, which is the right answer for a different team shape.

Is SSO on a self-serve Promptwatch plan?

No. SSO is listed under Enterprise and custom pricing, with white-label and dedicated support. No tool in our coverage publishes SSO on a self-serve plan, so a requirement for SSO is a requirement for an enterprise budget.

What does a read-only Promptwatch key hide?

On MCP it hides write tools entirely, so a chat session cannot bulk-create prompts or push a CMS draft. Citations and crawler analytics still show, because those are the read surfaces a stakeholder needs.