We use privacy-friendly analytics (Plausible) for aggregate site traffic. Privacy Policy
Connecting an account shouldn’t mean giving an app the keys to move your money. What read-only actually means in practice.
Vault & Compass

“Connect your bank” is a vague phrase. It can mean reporting, or it can mean movement. Those are different trust decisions, and most connect screens don’t make the difference obvious.
Read-only access (balances, transactions, holdings) lets an app show you information and fill a spreadsheet or dashboard. It can see what happened. It cannot make anything happen.
Payment or write permissions can initiate transfers. That’s a much higher bar, appropriate for bill pay and brokerage funding, and not required for budgeting sync. If a tool whose entire job is showing you your spending asks for the ability to move money, that’s worth a question.
Sheetful’s bank connections and Prismfolio’s brokerage connections are both built around read access to data you choose to link. Neither is a substitute for your bank’s bill pay, and neither is trying to be.
The blast radius of a compromised budgeting app should be embarrassment and the rotation of a token, not an unexpected wire. Scope is the part of security you can reason about without knowing anything about the vendor’s infrastructure: an access grant that has no transfer capability cannot be used to transfer, regardless of who ends up holding it.
Architecture can’t eliminate risk. A read-only breach still exposes your transaction history, which is genuinely sensitive. But it caps the worst case at disclosure rather than loss, and that ceiling is worth choosing deliberately.
The connection screen usually lists permissions in plain language before you approve. Read it. Aggregators like Plaid present the specific products an app requested, and “transactions” and “auth” are not the same grant.
After the fact, two places hold the record: the aggregator’s own portal, and your bank’s third-party access or connected-apps page. The bank’s view is the authoritative one, because it shows every grant regardless of which aggregator brokered it.
That last one matters most. Credential sharing hands over everything at once and leaves no way to revoke a single app.
Access granted in 2023 is still access today. Most people connect more apps than they remember, and abandoned tools keep syncing quietly. Revoking takes a minute per connection and shrinks your exposure permanently, which is a better return than almost anything else on a security checklist.
Privacy isn’t a slogan. It’s what the token is allowed to do when nobody’s watching.