Opidocs
FeaturesAI Agents

Permissions

Control who can access, interact with, and manage your AI agents.

Not every agent should be available to everyone. Permissions let you control who on your team can use each agent, keeping things organized and secure as your agent collection grows.

How permissions work

Each agent has its own permission settings that determine who can interact with it. You can configure these when you create the agent or update them at any time from the agent's settings.

There are two levels of access:

  • Users — Team members who can chat with and send tasks to the agent. They can use it but can't change its configuration.
  • Managers — Team members who can chat with the agent and also modify its settings, tools, personality, and knowledge connections.

By default, new agents are available to everyone in your organization. You can narrow this down to specific teams or individuals if the agent is only relevant to a subset of your team.

Configuring permissions

Open agent settings

Navigate to your agent in the AI Employees section and click into its settings.

Go to the Permissions tab

You'll see the current access configuration — who can use the agent and who can manage it.

Adjust access

Add or remove individuals and teams. Set each person or team as a User or Manager depending on the level of access they need.

If an agent handles sensitive information (like HR policies or financial data), restrict access to only the people who need it. You can always expand access later.

Restricting agent actions

Beyond who can use an agent, you can also limit what the agent itself is allowed to do. For example, you might allow an agent to search documents but prevent it from sending emails. This is managed through the Tools configuration — by disabling tools you don't want the agent to use.

Combining user permissions with tool restrictions gives you fine-grained control over both who uses the agent and what the agent can do.

What's next?

On this page