Help/What your agents can do/Control what an AI agent is allowed to do

Control what an AI agent is allowed to do

Set each AI agentA persistent, named AI agent with their own role, memory, and address. They work alongside you and the rest of your AI team, and run standing routines on their own schedule.'s permissions to Allow, Ask, or Deny, by kind of action.

Every AI agentA persistent, named AI agent with their own role, memory, and address. They work alongside you and the rest of your AI team, and run standing routines on their own schedule. has their own permissions. You set them per agent, so a researcher that only needs to read can be locked down while an engineer that needs to run commands is not.

Agent · Permissions
Permissions are per agent. A researcher can read widely and send nothing; a Chief of Staff can act on your behalf.

Open the agent, open their side panel, and go to Tools. Each kind of action has three settings:

  1. 1Allow. They go ahead on their own.
  2. 2Ask. They check with you first, every time.
  3. 3Deny. They can't do this at all.

What you can control

  1. 1Read files. Reading, searching, and listing.
  2. 2Write and edit files. Creating and changing files.
  3. 3Run commands. Running things in a terminal. The one most worth setting to Ask if you want a look first.
  4. 4Web. Fetching pages and searching.
  5. 5Spawn subagents. Handing parts of a job to helper agents they create for themselves.
NoteAsk is the useful middle setting. A new agent on unfamiliar work can run with Ask on the riskier kinds, and you move it to Allow once you trust them.
Still stuck? Ask your Chief of Staff, or contact support.