An AI agent gets less than you.
An AI agent never reaches further than the human it works for. Narrow what somebody may do, or take them off the team, and their AI agents narrow with them within minutes: what an AI agent may touch is looked up when it asks, not copied down the day somebody set it up.

Two lists, and the smaller one wins
Use only the AI agent's list and it floats free: take the human off the team and their AI agent carries on with whatever it was allowed months ago. Use only the human's list and the AI agent becomes whatever they are, which for an administrator is everything. So the platform reads both and keeps the overlap. Narrow either side and the AI agent narrows with it.
Looked up again, not remembered
The human's authority is read at the time of the call, not copied into the AI agent when it was set up. Change what somebody may do, or take them off the team, and their AI agents follow within minutes. If we cannot establish who the AI agent is acting for at all, it is refused outright rather than quietly dropped to read-only, because read-only still reads everything you have.
The most an AI agent is ever handed
There is a hard ceiling above both lists, the same for every AI agent on the platform rather than set human by human: see a project, work on a project, and start an AI agent. That is the widest an approved one can ever be, before the human's own limits narrow it further. One nobody has approved gets nothing at all at this step.
What an unapproved AI agent can doThe list is filtered, then checked again
An AI agent is shown only the tools its role covers, which keeps it from trying things it cannot have. That is tidiness, not the boundary. The boundary is the second check, when a tool is actually used: outside the role, it is refused and the refusal is written down. A tool nobody has put in a role is reachable only by full access, so a new one is never quietly handed to a narrow AI agent.
Which pages a human can open
You can also decide, human by human, which screens they see. Nobody is restricted until you restrict them, so switching this on changes nothing for anybody. Restricting somebody's view of one product does not silently close another. An administrator is never narrowed, so the last one cannot lock themselves out of the screen that hands access out.
- A page missing from somebody's menu is missing because the server refused it, not the other way round.
- Saving answers for the whole screen list, so restricting somebody to nothing at all is something you can actually say.
- Every save is one line on the record: who changed it, for whom, and what was opened and shut.
Two things worth knowing about
An administrator has no narrower list to compare against, so their AI agent is held to exactly what was approved for it and nothing wider: being approved by an administrator does not make an AI agent one. And because the limit comes from a human rather than a template, two AI agents doing the same job can end up with different limits. Decide who approves what, and that stops being a surprise.
Tell us what your AI agents are allowed to touch today.
Also in Governance
- ApprovalsAnything that cannot be undone is assigned to a human.Read the page
- Audit trail and evidenceWho did what, on a sealed record, exported when someone asks.Read the page
- AI agent securityA name, a limit, and somebody who can stop it.Read the page
- AI agent identityA human lets an AI agent in, and can stop it again.Read the page
- AI agent sign-insA sign-in expires sooner the more it can do.Read the page
- Approved modelsWhich models may run, who approved each one, and what it left behind.Read the page
- Scans and approved packagesApproved packages at the exact version, checked when used.Read the page