Connect ApparelMagic with a token from your own account. You decide how much Iris can see by choosing which ApparelMagic user that token belongs to, anywhere from a single stock lookup to running everything through ApparelMagic.
What Iris Can Do
An ApparelMagic token belongs to a user, and it carries exactly that user's permissions. So the question isn't what Iris is able to read, it's what you choose to give it. Two shapes we run today:
A retailer whose supplier runs ApparelMagic just wants to see stock and nothing more. Iris checks on-hand and available-to-sell quantity for a style, broken out by warehouse, and nothing else. No prices, no costs, no vendors, no orders, and no writes.
For a wholesale business running on ApparelMagic, the token belongs to a user with real permissions, and Iris works from it as the source of truth rather than a single lookup.
The boundary is structural, not a promise we're making. Iris can only ever reach what the token's user is allowed to reach, so a narrow setup stays narrow.
Connect
The only real decision is which ApparelMagic user the token belongs to, because that user's permissions become Iris's permissions. Everything after that is a copy and paste.
Use an existing ApparelMagic user whose access matches what you want Iris to see, or make one specifically for this. If you only want Iris to see stock, give that user access to stock and nothing else.
From that user's account, create an MCP token. It inherits their permissions automatically, so there's no separate scope list to configure.
Add it under ApparelMagic in your integration settings. Iris can answer from ApparelMagic straight away, within whatever that user is allowed to see.
Not sure which user to point it at? That's the one part worth a conversation, especially if the ApparelMagic account belongs to a supplier rather than to you.
Talk through the right scope