Dispatches
Trust · Athena Governance System · Permissions & identity

Inherit live permissions from every source system

Each user's rights flow from SharePoint, Snowflake, Salesforce, and the rest in real time. The agent acting for them gets the same rights.

A global professional services firm runs the platform inside its own tenant with red-team-hardened roles.

Agent forfinance.leadRead sales forecast fileCHECKED AGAINST THE SOURCEEntraSharePoint folderSnowflake schemaSalesforce objectFail closed · agentcannot readIf the permissionservice cannot bereached, the actiondoes not run
Fig. 01Each user's rights inherited from source systems in real time; fail-closed
  • SAML
  • OIDC
  • Okta
  • Entra
  • SCIM
  • Tenant-wide consent
  • Source-system permissions inherited per user
  • Fail-closed
  • Agent identities in your directory
The problem

One over-privileged account is a common shortcut

It is a common deployment pattern: one over-privileged identity, a copy of your documents in someone else's index, and a permission model that has to be maintained separately from the one you already have. The security review either fails or takes a year.

We are not inventing a new permissioning scheme outside the system of record.

Most enterprise AIAthena approachsvc-ai-bot identityFull access badgeVendor index copySeparate permissionOver-privileged, duplicated, hard to reviewPer-user identitiesLive permission checkTTL-only cacheNo copy of the store
Fig. 02Not inventing a new permissioning scheme outside the system of record
How it works

Identity. Inheritance. Enforcement. Attribution.

  1. Identity. Users sign in through your IdP: SAML/OIDC, Okta, Entra, SCIM provisioning. Agents have their own identity in your directory. Admin integrations use separate credentials from user-linked accounts; tokens are short-lived and scoped.

  2. Inheritance. Source-system permissions are read per user in real time. Files stay where they live; the cache is TTL-only. The source system remains authoritative.

  3. Enforcement. Fine-grained authorization per asset: view, edit, share across workspaces, groups, drives, portals; hide an asset from a specific user; restrict an agent to specific cell ranges. Owner-only computer mode. Fail-closed when the permission service is unreachable.

  4. Attribution. Every action carries the identity that performed it, human or agent, and is reversible.

01Your IdPSAML · OIDC · Okta ·Entra · SCIM02User and agentidentityAgents with their ownidentity in your …03Permission checkSource systems, livea person approves04ActionAttributed ·reversibleFail closed when permission service unreachable · no action · no cache
Fig. 03Identity, inheritance, enforcement, and attribution in every action
Examples

Ten thousand employees, one directory group.

A white-labeled portal provisioned by directory group. Each user sees Outlook, SharePoint, Teams, and the warehouse with their own rights. Enterprise search across 200 SharePoint sites with inherited permissions.

SSO group: all-employeesSales forecast Q3acceptedComp analysis draftacceptedFinance dashboardacceptedPartner agreementmissingExecutive briefingmissingSearch across 200 SharePoint3 results hidden by yourpermissions · each user seestheir own rights
Fig. 04Ten thousand employees provisioned by directory group with inherited permissions

Touchless O365 consent.

Tenant-wide consent once, instead of a click per user. Okta SSO. Non-licensed users can receive agent outputs by email or portal.

Athena wants toGrant tenant-wide O365 consent for allusersOkta SSO integrationNon-licensed users receive outputs via email/portalNo per-user click requiredWAITING FOR A PERSONConsent granted once for entire organizationAdmin · Entra tenant-wide consent · one-time
Fig. 05Admin consents once for the entire tenant; no click per user, Okta SSO enabled

Agents as first-class actors.

Each agent has an identity in your directory. You can see what it did, restrict what it can touch, and revoke it like any employee.

Entra user directoryTrigger · Agents as first-class actorsathena-finance-agent · Finance roleLast active recentlyCan restrict what it can touchRevoke like any employeeYou can see what it didand control access likeany directory userAgent identity
Fig. 06Each agent has an identity you can audit, restrict, and revoke

Row-level and range-level.

Wholesaler apps where each partner sees only its rows. Spreadsheets where the agent may edit the model tab and may not read the compensation tab.

Athena wants toEdit financial model and read sales dataAthena may edit Model!A1:Z500Athena may not read Comp!A:FRow-level and range-level controlWAITING FOR A PERSONAgent restricted to specific cell rangesFine-grained authorization per asset · range-level enforcement
Fig. 07Restrict an agent to specific cell ranges; each partner sees only its rows

Owner-only computer mode.

Limit who can create computers, open terminals, or touch files. A restrictive mode for the most regulated workspaces.

AnalystCreate computer and open terminalCHECKED AGAINST THE SOURCEWorkspace policyComputer mode settingAction blockedOnly workspace ownermay create computersor touch files
Fig. 08Owner-only computer mode denies non-owners from creating computers or opening terminals

Per-user cost governance.

Token cost by user, agent, and project. Budgets per run. Stale-workflow detection.

Token cost by user, agent, and projectUserAgentProjectBudget per runSetStale workflowsFlaggedUser AUser BUser CUser DUser EBudget bar per user, run limit
Fig. 09Cost dashboard shows token spend by user, agent, and project with budget enforcement
What customers say
“Digital worker, it gets spun up, it gets given access to the toolkits that it needs. It gets given access to the data that it needs. Just exists for the period it needs to exist to perform the task. And then it gets torn back down again afterwards.”
Audit lead · A global professional services firm
“I like that direction, that concept of the agent is the agent. It becomes an entity in its own right with its own ownership and its own missioning, and you get rid of the gray area and the blurry lines.”
Audit lead · A global professional services firm
“Obviously, you guys have really good security. We trust you guys with your security of what we do.”
Innovation lead · An AmLaw 100 firm
“It's a touchless, you know, seamless. Like, it just gives them whatever they have access to.”
Analytics lead · A Fortune 500 retailer
“Audit logging, user ID timestamp, data sources access, generated outputs. Yep.”
Analytics lead · A Fortune 500 retailer
“It's good to understand the capability of the platform. That how far, and how quickly you guys can get these things going [...] that has been impressive overall.”
VP-level AI leader · A Fortune 500 retailer
“Lets us get a lot more out of our data than [...] We can sit on top of all of the data in [our data warehouse] as opposed to just, like, our little ingested, you know, three gigabytes semantic models. I think we have a lot of power here.”
Analytics lead · A Fortune 500 retailer
“Gave Athena the spreadsheet, explained which column I was trying to figure out, and then ten secs it told me... exactly how the calculation was based on the other data.”
Analyst · A global manufacturer
“He wrote the entire stuff. By itself. And I was there, and I was thinking, alright. If I had to write all this stuff, I mean, I would've spent days, days, days.”
Manufacturing analyst · A global manufacturer
“I send that to the programmer and he said, alright. I read your file. I copied the section of the code because he has the right interface, and it works. Wow. Just like magic.”
Manufacturing analyst · A global manufacturer

Verbatim from customer calls. Customers anonymized.

Governance

Inherited permissions, live. Fail-closed enforcement.

  • Inherited permissions, live. No second permission model to maintain.

  • Fail-closed enforcement.

  • Short-lived scoped tokens; admin integrations separate from user-linked accounts.

  • Every action attributed to an identity and reversible.

What to plan for

Inherited permissions are only as clean as the source system's. If your SharePoint has an over-shared folder, the agent will see it exactly as its user does. We surface what we find; we do not fix your SharePoint.

FAQ

How do agents know what they may access?

They inherit live permissions from each source system, exactly like the person they work for.

How do we manage access?

Through your identity provider and directory groups.

Is access logged?

Yes. Every read and action is logged.

The rest of the platform

Related products and stories

Show us your worst over-shared folder.

We will show you the agent seeing exactly what its user sees, and nothing else.