Access and permissions

Which permission each AI Assistant screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (11)

Permissions by screen

ScreenMenuPermission needed
Assistant landing pageAI Assistant > AI Assistantai.use
ConversationAI Assistant > New Chatai.use (confirm a card: ai.act)
ComposerConversation > composerai.use
Confirmation cardConversation > answerai.act + the tool's own permission (e.g. document.draft, partner.manage, crm.manage)
Live voiceConversation > Liveai.use; Live voice switched on with a Google key
KnowledgeAI Assistant > Knowledgeai.use (read/search); ai.configure (manage)
My FilesAI Assistant > My Filesai.use
AgentsAI Assistant > Agentsai.use (see); ai.configure (create / change / test)
MCP ServersAI Assistant > MCP Serversai.configure
AI SettingsAI Assistant > Settingsai.configure (settings tabs); ai.activity (Activity log, Usage)
Feature switches and field rulesApplications > AI Assistant > Features / Fieldscompany.manage

All AI screens

RuleWhat the system does
View vs configureMenus MCP Servers and Settings hidden; GET/PUT ai/settings, ai/mcp/servers, POST agents / knowledge collections refused (403)

Confirmation card

RuleWhat the system does
AI never writes without confirmationNothing created by any message; records appear only after Confirm & Create by the requester
Confirm needs ai.actRefused (403); card shows 'Your role cannot confirm assistant actions.'
Only the requester confirms'Only the person who asked for this can confirm it.'

Conversation

RuleWhat the system does
Answers respect the user's permissions'You don't have permission to see that, so I can't answer it.'; no figures
Record scopeOnly their own team's customers / documents appear - same rows as the Contacts and Invoices screens
Field restrictionsPhone not in the answer, the table or the export
Company isolationOnly Company A data; another company's chat/file/action id -> 'Record not found.'
Prompt injection in a record does not actText is treated as data; no proposal card is created unless you ask; even if one is, nothing is saved without your click
Injection cannot export unrelated dataOnly the invoice is summarised; no customer list (baseline AIX-A1 - not verified by the team)
Chat ownership'Record not found.' (private) or 'Only the person who started this chat can change it.' (shared)

Settings

RuleWhat the system does
API keys maskedOnly has_api_key / has_google_key true; placeholder 'A key is saved - type to replace it'; key value never returned or logged

MCP Servers

RuleWhat the system does
MCP secret maskedhas_secret true; token not in the response, logs or activity
Outside tools start offAll tools OFF; write tools cannot be set READ_ONLY or NEVER_REQUIRE_CONFIRMATION; stdio/SSE/WebSocket refused

Settings > Security & privacy

RuleWhat the system does
Never-send fieldsThe model is not given phone (answer text does not quote it); activity input has no phone; the on-screen table still shows it if your role may see it

My Files

RuleWhat the system does
Private filesB: not listed; 'Record not found.'; attachment silently ignored; read_file 'That file is not available.'

Live voice

RuleWhat the system does
Live socket checksClosed with 4403 / 4401 / 4403 / 4404 respectively

Agents / Settings

RuleWhat the system does
Edit conflictsSecond save 'Somebody else changed this agent. Reload and try again.'

AI Settings > Activity log

RuleWhat the system does
Activity log needs ai.activityRefused (403)