Analytics keys, invoice bank details and invite links are no longer readable by every signed-in client
A signed-in client can no longer look up a venue’s analytics API secrets, invoice bank details, or the one-time links on buddy invites, private-event registrations and migration companion threads. Staff who already hold the matching settings or bookings permission still see those screens, including while Booking Bible support is signed in as the venue.
# Analytics keys, invoice bank details and invite links are no longer readable by every signed-in client Yesterday’s tenant security release closed venue-wide lookups on sixteen kinds of record. It left a short leftover list — analytics integration keys, the bank details on invoice settings, and the one-time links on buddy invites, private-event participants and migration companion threads — because closing those without moving the screens onto the server’s own authority would have emptied them while support was impersonating a venue. That leftover is now closed. ## What staff need to know **Nothing changes on the screens you use.** Analytics settings still need **Manage integrations**. Invoice / business settings still need **Edit business settings**. Private-event participant lists still need **Manage private events**. Buddy invites still need **Book on a client's behalf**. Migration companion threads still need **View migration status**. Owners and managers hold these by default; the front desk keeps private events and buddy invites. If a list looks empty after this change, it is a permission they do not hold rather than a fault. ## What clients see Nothing changes on the product. A client still opens their own buddy-invite link and their own private-event registration link. They can no longer read those one-time tokens, the venue’s analytics API secrets, or invoice bank details by talking to the database directly.
Clients can no longer change venue records or read other clients’ records
Invoices, point-of-sale records, messaging settings, member tags, catalog and event records, AI settings and migration imports can now only be changed by staff who hold the matching permission, and a client can no longer look up other clients’ invoices, receipts, message history, tags, scores or health records. Every screen keeps working; sixteen kinds of record now need a named permission to look