TEKIMAXALOS

The overlap of two lists, every call.

An agent never reaches further than its owner. Narrow what a person may do, or take them off the team, and their agents narrow with them within minutes. What an agent may touch is looked up when it asks, not copied down the day somebody set it up.

a desk by a window, the screen in use

Two lists, and the smaller one wins

Use only the agent's list and it floats free. Take the person off the team and their agent carries on with whatever it was allowed months ago. Use only the owner's list and the agent becomes whatever they are, which for an administrator is everything. So the platform reads both and keeps the overlap. Narrow either side and the agent narrows with it.

Looked up again, not remembered

The owner's authority is read at the time of the call, not copied into the agent when it was set up. Change what a person may do, or take them off the team, and their agents follow within minutes. If we cannot establish who the agent is acting for, it is refused outright rather than quietly dropped to read-only. Read-only still reads everything you have.

The most an agent is ever handed

There is a hard ceiling above both lists, the same for every agent here rather than set person by person. It covers three things: see a project, work on a project, and start an agent. That is the widest an approved one can ever be, before its owner's own limits narrow it further. One nobody has approved gets nothing at all at this step.

What an unapproved agent can do

The list is filtered, then checked again

An agent is shown only the tools its role covers, which keeps it from trying things it cannot have. That is tidiness, not the boundary. The boundary is the second check, when a tool is actually used: outside the role, it is refused and the refusal is written down. A tool nobody has put in a role is reachable only by full access. So a new one is never quietly handed to a narrow agent.

Which pages a person can open

You can also decide, person by person, which screens they see. Nobody is restricted until you restrict them, so switching this on changes nothing for anybody. Restricting somebody's view of one product does not silently close another. An administrator is never narrowed, so the last one cannot lock themselves out of the screen that hands access out.

  • A page missing from somebody's menu is missing because the server refused it, not the other way around.
  • Saving answers for the whole screen list, so restricting somebody to nothing at all is something you can actually say.
  • Every save is one line on the record: who changed it, for whom, and what was opened and shut.
A card listing the screens Dana Okafor may open: projects and documents open, approvals shut

Two things worth knowing about

An administrator has no narrower list to compare against, so their agent is held to exactly what was approved for it and nothing wider. Being approved by an administrator does not make an agent one. And because the limit comes from a person rather than a template, two agents doing the same job can end up with different limits. Decide who approves what, and that stops being a surprise.

Tell us what your agents are allowed to touch today.

Talk to us