Access that is explicit, scoped and revocable.
When an AI employee joins a workflow, the first question should be the same as for any hire: what exactly is it allowed to touch? Roles & Permissions makes access a deliberate grant — scoped to resources, limited in action, and revocable — for people and AI roles alike.
Access that grew by accident cannot be governed on purpose.
Permissions accumulate: shared drives open to everyone, accounts passed around, tools connected once and never reviewed. Introducing AI assistance into that environment means amplifying whatever access already exists — including the parts nobody would approve today.
Governance starts with being able to answer, precisely: this role can see these things, do these actions, and must ask a person for anything beyond.
- Standing access broader than anyone remembers granting
- AI tools connected with the permissions of whoever set them up
- No clean way to revoke or review access when roles change
- Sensitive records reachable by roles that never needed them
Role, resource, action, limit.
Access is modelled as explicit grants, applied consistently to human and AI roles.
Deliberate grants. No ambient access.
Within its role
- Scope access per role, per resource, per action
- Apply the same model to people and AI employees
- Route beyond-limit actions to Human Approvals
- Make grants reviewable and revocable as roles change
Always with people
- Grant standing or default access beyond a role’s scope
- Let any role — human or AI — expand its own permissions
- Describe specific identity or SSO integrations before they are validated [VALIDATE: confirm identity providers supported]
- Replace your own access-governance policies — it enforces them
See Roles & Permissions on one real workflow.
Bring us one operational pressure. We will show how this capability would apply, where authority would sit, and what the record would look like.