A global professional services firm runs the platform inside its own tenant with red-team-hardened roles.
Fig. 01Each user's rights inherited from source systems in real time; fail-closed
SAML
OIDC
Okta
Entra
SCIM
Tenant-wide consent
Source-system permissions inherited per user
Fail-closed
Agent identities in your directory
The problem
One over-privileged account is a common shortcut
It is a common deployment pattern: one over-privileged identity, a copy of your documents in someone else's index, and a permission model that has to be maintained separately from the one you already have. The security review either fails or takes a year.
We are not inventing a new permissioning scheme outside the system of record.
Fig. 02Not inventing a new permissioning scheme outside the system of record
How it works
Identity. Inheritance. Enforcement. Attribution.
Identity. Users sign in through your IdP: SAML/OIDC, Okta, Entra, SCIM provisioning. Agents have their own identity in your directory. Admin integrations use separate credentials from user-linked accounts; tokens are short-lived and scoped.
Inheritance. Source-system permissions are read per user in real time. Files stay where they live; the cache is TTL-only. The source system remains authoritative.
Enforcement. Fine-grained authorization per asset: view, edit, share across workspaces, groups, drives, portals; hide an asset from a specific user; restrict an agent to specific cell ranges. Owner-only computer mode. Fail-closed when the permission service is unreachable.
Attribution. Every action carries the identity that performed it, human or agent, and is reversible.
Fig. 03Identity, inheritance, enforcement, and attribution in every action
Examples
Ten thousand employees, one directory group.
A white-labeled portal provisioned by directory group. Each user sees Outlook, SharePoint, Teams, and the warehouse with their own rights. Enterprise search across 200 SharePoint sites with inherited permissions.
Fig. 04Ten thousand employees provisioned by directory group with inherited permissions
Touchless O365 consent.
Tenant-wide consent once, instead of a click per user. Okta SSO. Non-licensed users can receive agent outputs by email or portal.
Fig. 05Admin consents once for the entire tenant; no click per user, Okta SSO enabled
Agents as first-class actors.
Each agent has an identity in your directory. You can see what it did, restrict what it can touch, and revoke it like any employee.
Fig. 06Each agent has an identity you can audit, restrict, and revoke
Row-level and range-level.
Wholesaler apps where each partner sees only its rows. Spreadsheets where the agent may edit the model tab and may not read the compensation tab.
Fig. 07Restrict an agent to specific cell ranges; each partner sees only its rows
Owner-only computer mode.
Limit who can create computers, open terminals, or touch files. A restrictive mode for the most regulated workspaces.
Fig. 08Owner-only computer mode denies non-owners from creating computers or opening terminals
Per-user cost governance.
Token cost by user, agent, and project. Budgets per run. Stale-workflow detection.
Fig. 09Cost dashboard shows token spend by user, agent, and project with budget enforcement
What customers say
“Digital worker, it gets spun up, it gets given access to the toolkits that it needs. It gets given access to the data that it needs. Just exists for the period it needs to exist to perform the task. And then it gets torn back down again afterwards.”
Audit lead · A global professional services firm
“I like that direction, that concept of the agent is the agent. It becomes an entity in its own right with its own ownership and its own missioning, and you get rid of the gray area and the blurry lines.”
Audit lead · A global professional services firm
“Obviously, you guys have really good security. We trust you guys with your security of what we do.”
Innovation lead · An AmLaw 100 firm
“It's a touchless, you know, seamless. Like, it just gives them whatever they have access to.”
Analytics lead · A Fortune 500 retailer
“Audit logging, user ID timestamp, data sources access, generated outputs. Yep.”
Analytics lead · A Fortune 500 retailer
“It's good to understand the capability of the platform. That how far, and how quickly you guys can get these things going [...] that has been impressive overall.”
VP-level AI leader · A Fortune 500 retailer
“Lets us get a lot more out of our data than [...] We can sit on top of all of the data in [our data warehouse] as opposed to just, like, our little ingested, you know, three gigabytes semantic models. I think we have a lot of power here.”
Analytics lead · A Fortune 500 retailer
“Gave Athena the spreadsheet, explained which column I was trying to figure out, and then ten secs it told me... exactly how the calculation was based on the other data.”
Analyst · A global manufacturer
“He wrote the entire stuff. By itself. And I was there, and I was thinking, alright. If I had to write all this stuff, I mean, I would've spent days, days, days.”
Manufacturing analyst · A global manufacturer
“I send that to the programmer and he said, alright. I read your file. I copied the section of the code because he has the right interface, and it works. Wow. Just like magic.”
Manufacturing analyst · A global manufacturer
“Digital worker, it gets spun up, it gets given access to the toolkits that it needs. It gets given access to the data that it needs. Just exists for the period it needs to exist to perform the task. And then it gets torn back down again afterwards.”
Audit lead · A global professional services firm
“I like that direction, that concept of the agent is the agent. It becomes an entity in its own right with its own ownership and its own missioning, and you get rid of the gray area and the blurry lines.”
Audit lead · A global professional services firm
“Obviously, you guys have really good security. We trust you guys with your security of what we do.”
Innovation lead · An AmLaw 100 firm
“It's a touchless, you know, seamless. Like, it just gives them whatever they have access to.”
Analytics lead · A Fortune 500 retailer
“Audit logging, user ID timestamp, data sources access, generated outputs. Yep.”
Analytics lead · A Fortune 500 retailer
“It's good to understand the capability of the platform. That how far, and how quickly you guys can get these things going [...] that has been impressive overall.”
VP-level AI leader · A Fortune 500 retailer
“Lets us get a lot more out of our data than [...] We can sit on top of all of the data in [our data warehouse] as opposed to just, like, our little ingested, you know, three gigabytes semantic models. I think we have a lot of power here.”
Analytics lead · A Fortune 500 retailer
“Gave Athena the spreadsheet, explained which column I was trying to figure out, and then ten secs it told me... exactly how the calculation was based on the other data.”
Analyst · A global manufacturer
“He wrote the entire stuff. By itself. And I was there, and I was thinking, alright. If I had to write all this stuff, I mean, I would've spent days, days, days.”
Manufacturing analyst · A global manufacturer
“I send that to the programmer and he said, alright. I read your file. I copied the section of the code because he has the right interface, and it works. Wow. Just like magic.”
Manufacturing analyst · A global manufacturer
Verbatim from customer calls. Customers anonymized.
Inherited permissions, live. No second permission model to maintain.
Fail-closed enforcement.
Short-lived scoped tokens; admin integrations separate from user-linked accounts.
Every action attributed to an identity and reversible.
What to plan for
Inherited permissions are only as clean as the source system's. If your SharePoint has an over-shared folder, the agent will see it exactly as its user does. We surface what we find; we do not fix your SharePoint.
FAQ
How do agents know what they may access?
They inherit live permissions from each source system, exactly like the person they work for.
How do we manage access?
Through your identity provider and directory groups.