Access and permissions
Which permission each AI Assistant screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (11)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Assistant landing page | AI Assistant > AI Assistant | ai.use |
| Conversation | AI Assistant > New Chat | ai.use (confirm a card: ai.act) |
| Composer | Conversation > composer | ai.use |
| Confirmation card | Conversation > answer | ai.act + the tool's own permission (e.g. document.draft, partner.manage, crm.manage) |
| Live voice | Conversation > Live | ai.use; Live voice switched on with a Google key |
| Knowledge | AI Assistant > Knowledge | ai.use (read/search); ai.configure (manage) |
| My Files | AI Assistant > My Files | ai.use |
| Agents | AI Assistant > Agents | ai.use (see); ai.configure (create / change / test) |
| MCP Servers | AI Assistant > MCP Servers | ai.configure |
| AI Settings | AI Assistant > Settings | ai.configure (settings tabs); ai.activity (Activity log, Usage) |
| Feature switches and field rules | Applications > AI Assistant > Features / Fields | company.manage |
All AI screens
| Rule | What the system does |
|---|---|
| View vs configure | Menus MCP Servers and Settings hidden; GET/PUT ai/settings, ai/mcp/servers, POST agents / knowledge collections refused (403) |
Confirmation card
| Rule | What the system does |
|---|---|
| AI never writes without confirmation | Nothing created by any message; records appear only after Confirm & Create by the requester |
| Confirm needs ai.act | Refused (403); card shows 'Your role cannot confirm assistant actions.' |
| Only the requester confirms | 'Only the person who asked for this can confirm it.' |
Conversation
| Rule | What the system does |
|---|---|
| Answers respect the user's permissions | 'You don't have permission to see that, so I can't answer it.'; no figures |
| Record scope | Only their own team's customers / documents appear - same rows as the Contacts and Invoices screens |
| Field restrictions | Phone not in the answer, the table or the export |
| Company isolation | Only Company A data; another company's chat/file/action id -> 'Record not found.' |
| Prompt injection in a record does not act | Text is treated as data; no proposal card is created unless you ask; even if one is, nothing is saved without your click |
| Injection cannot export unrelated data | Only the invoice is summarised; no customer list (baseline AIX-A1 - not verified by the team) |
| Chat ownership | 'Record not found.' (private) or 'Only the person who started this chat can change it.' (shared) |
Settings
| Rule | What the system does |
|---|---|
| API keys masked | Only has_api_key / has_google_key true; placeholder 'A key is saved - type to replace it'; key value never returned or logged |
MCP Servers
| Rule | What the system does |
|---|---|
| MCP secret masked | has_secret true; token not in the response, logs or activity |
| Outside tools start off | All tools OFF; write tools cannot be set READ_ONLY or NEVER_REQUIRE_CONFIRMATION; stdio/SSE/WebSocket refused |
Settings > Security & privacy
| Rule | What the system does |
|---|---|
| Never-send fields | The model is not given phone (answer text does not quote it); activity input has no phone; the on-screen table still shows it if your role may see it |
My Files
| Rule | What the system does |
|---|---|
| Private files | B: not listed; 'Record not found.'; attachment silently ignored; read_file 'That file is not available.' |
Live voice
| Rule | What the system does |
|---|---|
| Live socket checks | Closed with 4403 / 4401 / 4403 / 4404 respectively |
Agents / Settings
| Rule | What the system does |
|---|---|
| Edit conflicts | Second save 'Somebody else changed this agent. Reload and try again.' |
AI Settings > Activity log
| Rule | What the system does |
|---|---|
| Activity log needs ai.activity | Refused (403) |