Permissions Arolead asks Meta for
Every permission in the connect flows, what it is used for, and how to revoke it
When you connect an account, Meta shows the permissions Arolead requests. Every one of them maps to a feature you can see in the product. Arolead's app has passed Meta's App Review for these permissions, which is what makes the automation allowed rather than a policy risk.
Instagram (Connect Instagram only)
| Permission | Used for |
|---|---|
instagram_business_basic | Reading the account's profile and media so you can pick posts |
instagram_business_manage_comments | Reading comments and posting public replies |
instagram_business_manage_messages | Reading DMs and sending replies, including private replies to comments |
instagram_business_content_publish | Scheduling posts and Reels |
instagram_business_manage_insights | The analytics dashboard |
Facebook Page and its linked Instagram (Connect via Facebook)
| Permission | Used for |
|---|---|
pages_show_list | Listing the Pages you manage so you can choose one |
pages_manage_metadata | Subscribing the Page to comment and message webhooks |
pages_read_engagement | Reading Page comments |
pages_messaging | Messenger DMs |
pages_manage_posts | Scheduling Facebook posts |
instagram_basic, instagram_manage_comments, instagram_manage_messages, instagram_content_publish, instagram_manage_insights | The same Instagram features as above, through the linked Page |
business_management | Reading the Business Portfolio the Page belongs to |
WhatsApp permissions are granted inside Meta's Embedded Signup, scoped to the WhatsApp Business Account you connect. They cover reading and sending messages, managing templates and reading the account's status.
What Arolead never does
- It never sees or stores your Facebook, Instagram or WhatsApp password. Connection is Meta's own login.
- It never posts, replies or messages except through an automation or an inbox reply you created.
- It never reads other people's accounts, only the accounts you connected.
Revoking
Disconnect in Accounts: the connection is removed and the account's automations are deactivated. You can also revoke Arolead from Facebook under Settings → Business integrations, or from Instagram under Settings → Apps and websites. Either one stops all access immediately.