Learn

AI Agent Permissions: Why a Label Isn't a Wall

When a company puts an AI agent to work in Slack or Microsoft Teams, the first serious question is usually about AI agent permissions: who gets to see what? The instinct is to treat the agent like a new hire — give it a role, assign it to a department, mark certain topics "executives only." Here's the uncomfortable truth most vendors skip: inside a single AI agent, those labels don't protect anything. Understanding why — and what actually works — is the difference between a safe rollout and a quiet data leak waiting for a clever question.

One brain, one pool of knowledge

A single AI agent is one brain. Everything it has been given — documents, notes, history, connections to your systems — sits in one pool. Anyone who's allowed to talk to that agent can, with the right question, reach anything in the pool. Tags like "assigned to finance" or "HR only" are organizational conveniences, like naming a folder on a shared drive. They are not locks. If you've ever worked somewhere that "confidential" was just a folder name anyone could open, you already understand the problem. The org chart can't be a label you stick on information. It has to be a wall you build.

The wall is a separate agent

The real security boundary isn't a label inside one agent — it's a second agent. Each agent gets its own memory, its own files, its own system access. An agent that was never given the financials cannot leak the financials. No clever question can extract what isn't there.

So your org chart becomes a set of agents:

  1. An executive agent that holds financials and strategy
  2. An operations agent that can touch systems and settings
  3. A separate agent per client or contractor engagement, which knows only that engagement
  4. A general company agent — the one everyone chats with daily — that simply never holds the sensitive material

Three locks on top

Separate agents are the foundation. Three enforcement layers make it stick:

  1. Routing. Each Slack channel or Teams team is wired to exactly one agent. A contractor channel lands on the contractor agent and physically cannot reach the executive one. The hallway only leads to one room.
  2. The front door. An allowlist controls who can address the agents at all. If you're not on the list, there's no conversation to begin with.
  3. People permissions. For anyone with deeper access, roles define which agents they may use, whether they can see other people's sessions, and a hard ceiling on what they can change — read-only versus full control. Outside contractors can be confined to a disposable sandbox: an isolated environment that can't modify anything and gets thrown away afterward.

Notice what these layers do: they enforce the separation. None of them substitutes for it. If sensitive data lives inside an agent someone can reach, a determined question will eventually find it.

The honest limit

Everything above assumes one trust zone: all your agents running in one place, managed by your own admins. Those admins can reach all of it — that's what administration means. If certain data genuinely must be beyond even them — regulated client records, acquisition talks, legal holds — it needs its own fully separate deployment, with its own administrator. Deciding early which data belongs in that bucket is cheap. Migrating it out later is not.

Start from the leaks, not the org chart

The approach that works isn't mirroring your whole org chart in software. Start with one question: what must never cross a line? Client A's data to client B. Payroll to the general staff channel. Contractor eyes to company strategy. Build an agent wall at each of those lines and stop. Most companies need fewer walls than they expect — but the ones they need have to be real.

Find where AI fits — safely.

Tell us how your team is structured and what can't leak. We'll map which walls you actually need — usually fewer than you'd guess.

Tell us about the operation

About you
About the business
About the opportunity

Your details are sent to Big Timber and stored so we can respond. We read every one and reply personally.