AI agent permissions

AI Agent Permissions Checklist for NZ Businesses

Decide what your AI agent can read, draft, update, send, publish, and never touch

AI agent permissions define the exact access and authority an agent has before it connects to live business systems.

The safest first AI agent is not the most powerful one. It has a narrow job, trusted sources, clear permissions, visible logs, and a human approval gate.

Use this checklist before connecting an agent to your CRM, inbox, website, task manager, reporting tools, or customer records. For a workflow-specific map, start with the $1,000 AI Agent Assessment.

What are AI agent permissions?

AI agent permissions are the rules that define what an agent can access, prepare, change, send, publish, delete, or escalate. They turn "use AI in the business" into specific operating boundaries.

Permissions are workflow rules, not just software settings

A tool setting might allow CRM, inbox, folder, or website access. A business permission decides what the agent may do with that access. Reading a note is not the same as changing a deal stage. Drafting a response is not the same as sending it.

Permissions connect to governance and approval

Permissions should sit inside a wider AI workflow governance checklist. Governance names the owner, sources, risks, logs, escalation path, and approval gate. Permissions make the boundary operational.

The six permission levels to define before build

Most workflows can be scoped with six permission levels. Write each separately instead of using a vague label like "CRM access" or "website access."

1. Read permissions

Read permission means the agent can view approved information: CRM fields, call notes, product pages, SOPs, spreadsheets, reports, templates, or public pages. Start narrow. Give the agent only the source material required.

2. Draft permissions

Draft permission means the agent can prepare output for review. This is usually the safest starting point. The agent may draft an email, CRM summary, article outline, management brief, support response, task list, or website recommendation. The output stays a draft until approved.

3. Recommend permissions

Recommend permission means the agent can suggest a next action but cannot take it alone. It may recommend which opportunities need follow-up, which pages need review, or which workflow should be improved next.

4. Update permissions

Update permission means the agent can change a record or system. Treat this as higher risk. Low-risk updates may include adding an internal note, tagging a draft, or logging that a review happened. Higher-risk updates include changing deal stages, customer records, pricing fields, permissions, public content, or delivery commitments.

5. Send or publish permissions

Send and publish permission means the agent can communicate externally or change public material. This should not be granted by default. Customer emails, proposals, website pages, newsletters, proof claims, pricing pages, legal wording, privacy text, and public schema should usually require human review. Use AI Approval Gates for Business Automation to map the stop point.

6. Delete and admin permissions

Delete, credential, billing, user-management, DNS, integration, and admin permissions should stay blocked unless there is a specific, tested reason to allow them. Usually, the agent can prepare a recommendation and a human can make the admin change.

AI agent permissions checklist

Use this checklist before connecting any agent to live tools.

1. Name the workflow first

Write the job in one sentence: "This agent helps [team] prepare [output] from [sources] so [person] can approve [decision or action]." If you cannot write that sentence, the permission map is not ready.

2. List approved sources

Name every source the agent can use: CRM fields, folders, spreadsheets, websites, policies, templates, inbox labels, meeting notes, reports, or knowledge-base pages. Mark sensitive sources clearly.

3. Mark each permission as read, draft, recommend, update, send, publish, delete, or blocked

Do not approve a system as one bundle. Break permissions into actions. A CRM agent may read records, draft notes, recommend priorities, update an internal task, and remain blocked from sending messages or changing deal stages.

4. Define the human approval point

Write exactly where the agent stops and who reviews the work. The reviewer should check source accuracy, privacy risk, tone, commercial impact, customer context, claim safety, and workflow fit.

5. Set the exception path

Tell the agent when to stop early. Escalate when sources conflict, data is missing, a customer is upset, a request is outside scope, sensitive information appears, or the output could affect trust, money, delivery, staff, legal, privacy, or public claims.

6. Keep a permissions log

Record what the agent accessed, prepared, changed, escalated, and what the human approved or rejected. Logs show whether to expand, reduce, or pause permissions.

Permission examples by agent type

Permissions are easier to design when they are tied to a real workflow.

Sales and CRM agent

A sales agent might read enquiry details, call notes, public company information, and selected CRM fields. It can draft follow-up emails, prepare lead fit notes, and recommend next actions. It should not send outreach, discount, promise dates, or change important CRM fields without approval. For a sales-specific boundary, read AI CRM Automation for NZ Sales Teams.

Website and SEO agent

A website agent might read public pages, analytics summaries, issue lists, and approved content briefs. It can draft title tags, FAQ improvements, broken-link notes, schema observations, and refresh recommendations. It should not publish, change forms, edit pricing, invent proof, alter legal wording, or touch DNS without review.

When not to expand AI agent permissions

Useful agents earn more permission through reliable output. They should not receive wider access just because the tool can technically support it.

No one owns review

If no one has time or authority to review the agent output, do not add send, publish, update, delete, or admin permissions. A human approval gate only works when someone is accountable.

The action affects trust

Customer relationships, pricing, public claims, privacy, legal wording, staff matters, and finance decisions need deliberate review. The agent can still prepare the work. The authority stays with a person.

How the AI Agent Assessment maps permissions

The AI Agent Assessment turns a permission checklist into a build decision for one real workflow.

What the assessment clarifies

The assessment maps the workflow owner, approved sources, required tools, permission levels, human approval gates, exception rules, data readiness, and success measure. It also decides whether the agent should stay draft-only, use limited update access, or wait.

Start smaller than your ambition

A narrow draft-and-review workflow often teaches more than a broad autonomous build. Once the agent prepares useful work, the business can decide what to expand and what should remain blocked.

Frequently asked questions

What permissions should an AI agent have first?

Most AI agents should start with narrow read, draft, and recommend permissions. Update, send, publish, delete, admin, billing, credential, and sensitive-data permissions should begin as blocked or human-approved.

Can an AI agent update CRM records automatically?

It can if connected to the right tools, but automatic CRM updates should start small. Internal notes and low-risk tags may be suitable after testing. Deal stages, forecasts, pricing, and customer commitments should require approval.

Should AI agents be allowed to send customer emails?

Not by default. A safer first workflow is for the agent to draft emails and show source notes so a person can review tone, accuracy, privacy, and context before sending.

What is the difference between access and permission?

Access is what a system technically allows the agent to reach. Permission is the business rule for what the agent may do with that access. An agent may access a CRM while still being blocked from changing important fields.

How often should AI agent permissions be reviewed?

Review permissions after the first real outputs, after any system or workflow change, and before granting broader access. The permissions log should show whether to expand or reduce scope.

Next step

Do not give an AI agent broad system access and hope the workflow stays safe. Name the workflow, narrow the sources, separate permissions, and keep human approval in front of consequential actions.

If you want a permission map for your first agent workflow, book the $1,000 AI Agent Assessment. AI Agent Agency will help decide what the agent can read, draft, update, send, publish, or never touch.