📸 Screenshot to add: Security & Access screen (roles and permissions).
The three pillars
Who has access
Each person sees only the agents, data, and screens they’re allowed to. Access per person and per role.
What needs approval
Sensitive actions wait for a human’s “ok” before they happen.
What happened
A record of actions for audit and trust.
Roles and permissions
iTeam uses roles to keep it simple: instead of configuring person by person, you define what each role can do.Access to an agent extends to its resources: someone who can’t see the agent won’t see its widgets or its data. Consistent protection end-to-end.
Human approvals
For actions that require caution (sending something external, changing critical data), you can require human approval. The agent prepares the action and waits for your signal — autonomy with a handbrake.1
Define which actions require approval
2
The agent pauses and notifies when it reaches one of them
3
You approve or reject — and it's recorded
Security best practices
Least privilege
Grant only the access each person and agent needs.
Approval on the sensitive
Keep irreversible actions under human review.
Credentials in the right place
Register keys under APIs — never in conversations.
Review access periodically
Remove access from those who no longer need it.
Agent access by area (area lock)
Some agents deal with sensitive matters of a specific area (e.g. Finance, Legal, HR). For those, there’s the “Only the area can access” lock: when turned on, only the people of that area can access and configure the agent — even if they had access through another path.1
Set the agent's area
The lock only works if the agent has an area set. Without an area, there’s no way to restrict by area.
2
Turn on “Only the area can access”
On the agent, enable the lock. From then on, access is restricted to the people of the area — and this restriction overrides other permissions (individual or per-project access doesn’t bypass the lock).
3
Owner and Admin still see it
The company’s owner and administrators still see and configure the agent. The lock closes the door for everyone else, not for administration.
Think of the lock as an “area-only” gate: it overrides the agent’s other access settings. Anyone not from the area can’t get in — neither to use nor to configure — except Owner/Admin.
Next steps
Settings
Company preferences (language, timezone, identity).
Agents
Define each agent’s access.
