Permissions carry over from the source systems. A fact from a private channel keeps the private channel's audience, a doc from a restricted drive keeps its restriction, and answers respect the asker's access.
Heidi does not invent a new permission model to configure from scratch. She inherits what your systems already say, per fact, and enforces it at recall time.
API access follows the same rule: tokens can be bound to a person, so everything a script reads respects that person's permissions.