Skip to main content
Each Agent has its own access. Give it only the resources needed for its current responsibility, then review sensitive actions before they continue.

Start with the responsibility

Before adding access, describe the Agent’s responsibility in one sentence. Then ask what it genuinely needs to complete that work. Access should answer a clear reason, such as:
  • read reference files to prepare a summary;
  • update one report in a specific file space;
  • use one approved Connection to find information;
  • run one tool required for the result.
Avoid adding access “just in case.” It is easier to understand an Agent when each permission has a visible purpose.

Choose the right access

Open the Agent’s access settings and review:
  • built-in capabilities it may use;
  • file spaces it may read, update, or delete;
  • Connections it may use;
  • data or other resources available to it.
Start with read access or a test resource. Add create, change, or delete access only when the responsibility requires it.

Use approvals

Some actions need a person to review and approve them. A useful approval should show:
  • what the Agent is about to do;
  • which resource will change;
  • why the action is needed;
  • whether it can be reversed.
Do not approve an action you do not understand. Ask the Agent to explain it in plain language first. A Scheduled Task cannot bypass the same approval.

Review regularly

Review an Agent’s access when:
  • its responsibility changes;
  • a project ends;
  • a connected account changes;
  • a Scheduled Task is no longer needed;
  • files or data move to a different place.
Remove access that no longer has a clear purpose.
Small access is easier to trustBegin with the smallest useful scope. Increase it only after the Agent has shown why the additional access is needed.