Agent knowledge and access
An agent has its own data permissions, independent of yours. What that means, who you can share an agent with and what each agent role can do.
In Datify an agent is a colleague of its own, not your extended arm. It therefore carries its own access badge – you decide which doors it opens, and separately who is allowed to call that colleague in.
These are two independent things, and most misunderstandings come from mixing them up.
Which datasets it has access to and with what role. This has nothing to do with your personal permissions.
Who can use it, edit it and share it further.
You configure a new colleague's badge according to what they are meant to do, too – not according to where you happen to be able to go.
Giving the agent its data
Adding a dataset
Add it in the Knowledge section with Add. Only datasets you manage yourself are offered – you cannot give the agent someone else's.
| Role | What it may do with the data |
|---|---|
| Reader | Reads the data. Refuses to change a record. |
| Editor | Reads and changes the data. The change appears in the change summary and can be undone. |
| Manager | Additionally changes the structure, just like a person with this role. |
An empty list does not mean "everything"
Without an assigned dataset the agent has no access to any workspace data. It does not inherit your permissions – it is a colleague with a blank badge who gets through no door at all. It can still chat, use other tools and run from tasks; it just cannot reach the tables.
Datasets you cannot see
A dataset the agent has but you have no access to appears in its settings as a name with an icon and no link; you cannot change its role. So you can see what the agent works with, but you cannot get inside through it.
The agent in dataset permissions
It works the other way round too. An agent is now a full participant in dataset permissions: the Add user, group or agent dialog offers them under Agents. A dataset manager can therefore give the agent access or take it away without having access to the agent itself – they see only its name, not its instructions or conversations.
Sharing an agent with a colleague
Open the agent settings and scroll to Access.
Search for a user or a group.
A newly added person gets Reader. Raise the role as needed.
| Role | What it can do |
|---|---|
| Reader | Can use the agent in conversations but cannot change its settings. |
| Editor | Can use the agent and edit its instructions, model, knowledge and tasks. Cannot manage access or the spending limit. |
| Manager | Can use the agent, change all of its settings, manage other people's access and set the spending limit. |
Groups work as with other permissions: the highest role from all sources applies. Someone with Reader directly and Editor through a group is an Editor, and a change of membership takes effect without you reconfiguring anything on the agent.
The role on an agent is separate from the role in the workspace. Even a manager of a dataset the agent uses does not automatically see the agent.
Before you share an agent
This is the most important paragraph of the article. Sharing an agent lends out a colleague together with their access badge.
Whoever you share it with can ask it anything from a dataset they cannot see themselves – just as if they had asked a colleague with wider rights to look it up for them. The app says so directly above the knowledge list: The agent uses its own data permissions. Anyone who can use the agent can use data through it without having direct access themselves.
| True | Not true |
|---|---|
| The agent answers from data the colleague cannot reach. | The colleague does not gain access to that data. Their own permissions do not change. |
| An answer may mention a record from such a dataset. | The link to it will not open – it is inactive and carries the note You don't have access to this item. |
| Anyone with Reader or higher can use the agent. | Nobody sees anyone else's chats; personal conversations stay private. |
So before you give an agent a sensitive table, think it through the way you would decide who gets the keys to the filing cabinet. You are not deciding just for yourself, but for everyone you later share the agent with.
The workspace administrator
An administrator sees and manages every agent in the workspace without it being shared – its settings, version history, permissions and spending limit. They do not appear as a row in the agent's permission list.
Two boundaries apply to them as well:
- they do not see anyone else's personal chats,
- an agent left without a manager must first be taken over with Take over – that writes them into the permissions as a manager.
What to watch out for
An agent must always have at least one manager. You cannot lower the role of the last remaining one or remove them; the app writes The agent must retain at least one manager.
Changing your own role is confirmed. When you lower your own role or remove your own access, Datify asks first; after removal the agent disappears from the overview and the settings close.
Removing access also hides that person's personal chats. They are not deleted – as soon as you give the access back, they reappear as they were.