Read-only outside Candor
Candor does not move money, trade, pay bills, open accounts, cancel subscriptions, file taxes, or change external accounts. It only keeps the financial context and follow-through your agent needs inside Candor.
Candor keeps connected accounts, evidence, plans, and past decisions organized. Your agent uses that picture to show what changed, recommend what fits, and prepare action only under the authority you grant it.
Candor does not move money, trade, pay bills, open accounts, cancel subscriptions, file taxes, or change external accounts. It only keeps the financial context and follow-through your agent needs inside Candor.
Provider access credentials stay in Candor-controlled backend systems. They are not stored in the CLI, local files, browser local storage, or agent prompts.
On macOS, Windows, and Linux, the CLI stores its OAuth refresh credential in native operating-system credential storage by default. Headless hosts can explicitly use a user-restricted credential file; Candor never falls back silently.
Candor authorizes an OAuth client grant or browser session, not each individual agent process. Any agent that can use an authorized CLI or remote MCP client under that grant can access the financial data in its scopes.
Financial reads are audited at a high level: who or what accessed which kind of data, when, and roughly how much was returned. Audit records are designed not to become raw financial-data dumps.
You can disconnect institutions, revoke authorized client access, export organized Candor data, and delete Candor data from account controls.
Candor can surface facts like duplicate charges, subscription changes, avoidable fees, idle cash yield gaps, common options, and missing context. Those are decision inputs, not permission to act.
If your agent drafts a message, opens a browser, cancels a service, moves money elsewhere, trades, files paperwork, or makes any external change, that happens outside Candor under the permission model you gave that agent.