Glossary
Target Invite
How a target company grants access. The investor sends the target a signed link; whoever holds the keys there (often the CEO, CFO or an admin) opens it. The link presents the Data Processing Agreement; accepting it is logged as a consent event. The target then connects QuickBooks, one CRM (HubSpot or Salesforce), GitHub, Jira and Slack read-only, in their own session. The investor never sees a credential.
Why it matters
Who connects is the first thing a target's counsel asks. In a Zoe case the investor never touches a credential and never sits in the target's OAuth flow. The target's own leadership accepts the Data Processing Agreement, sees the scopes, and grants access in their own session. That is what makes the read defensible on both sides of the table.
How Zoe reads it
The investor requests the connections from inside the case. Someone at the target, often the CEO or CFO, opens a signed link, is shown the DPA, and accepts it; the acceptance is logged as a consent event. They then connect QuickBooks, one CRM (HubSpot or Salesforce), GitHub, Jira and Slack read-only. Each connection is scoped and can be revoked from the source system at any time. Connection status updates in the case.