Skip to main content
THE CLIENT HOLDS THE DIAL

Eight toggles they own. One line nobody crosses.

Every client decides what their reseller can see and change, toggle by toggle, and can change their mind at any time. Credentials are not on the list, because credentials are never on the list.

For the client

The Manage Reseller panel.

When a workspace is managed by a reseller, a Manage Reseller item appears in the client’s Reseller sub-navigation. That panel is where all of this is decided.

They see who you are. The panel shows your company name, your contact person, a clickable email address, and the month you were certified.
They set the scope. Eight toggles, three of them marked SENSITIVE. Nothing is granted by assumption.
They can change it whenever. Saving sends only the toggles that actually changed, so flipping one off never quietly resets another.
A client who is not managed by anyone sees a single line instead: “Your workspace is not currently managed by a reseller.” If a client tells you the panel is missing, that is usually because the relationship has not finished attaching yet. See Onboarding a new client.
Try it

What each toggle actually unlocks.

Permissions are abstract until you see them as doors. Switch the toggles below to watch a client workspace open up. This is the real mapping the app uses.

Grant a permission, see what opens
Home
Agents
Onboarding
Impact
Apps
Skills
Memory
Files
Calendar
Settings
Marketplace
Learn
Support
Reseller
Projects
Chat History without Prompts & Instructions opens Home in view-only mode. You can read the conversation history, but the composer stays disabled.
Always open, no permission needed Always locked, whatever is granted
Two areas are locked in every delegated session regardless of what the client grants: the Reseller section itself, and Projects. You cannot use a client’s workspace to manage your own reseller account, and the planning surface has no delegated permission defined yet.
The list

Eight permissions, in the order the client sees them.

Three carry a SENSITIVE marker. That marker is a prompt to think, not a block, and the client can still grant them.

Prompts & Instructions
Edit agent configuration, including system prompts and instructions on this workspace’s agents.
On
Apps and MCP
Manage the Apps section, including tools, MCP servers, and connections that do not require credentials.
On
Skills
Install, enable, disable, or remove skills.
On
Agent Memories
View and modify what agents learned while working, including memories formed during customer interactions.
Off
Files SENSITIVE
Audit, replace, or remove proprietary documents, PDFs, and datasets the agents reference.
Off
Calendar & Schedules
View and edit scheduled agent runs, recurring jobs, and calendar-connected workflows.
On
Chat History SENSITIVE
Read the full conversation history between the client’s team and their agents.
Off
Billing summary SENSITIVE
View aggregate plan usage. Card details and invoice documents are never included.
Off
Credentials & API keys HARD LIMIT
Server-enforced permanent restriction. There is no toggle for this row.
always off

The exact wording each client reads is longer than the summaries above. Two are worth quoting in full, because they draw lines that surprise people.

Apps and MCP, in the client's own words

“Manage the Apps section, including tools, MCP servers, and app connections that don’t require credentials. Installing credential-based apps, connecting OAuth apps, and disabling or modifying anything tied to API keys, OAuth tokens, or other secrets is always off-limits, regardless of this setting.”Read that last clause carefully. Granting this permission does not let you finish a connection that needs a login. Nothing does. See Apps, tools and integrations.
Files: “Audit, replace, or remove proprietary documents, PDFs, and datasets your agents reference. Distinct from Memories, Files are the static source assets you uploaded.”Agent Memories: “View and modify ephemeral agent state, including memories formed during customer interactions.”They are genuinely different stores with different permissions. Files, memories and chat history explains why granting one does not imply the other, and why the Agent Memories permission does not open a memory editor.
“View aggregate plan usage. They never see your credit card or invoice PDFs.”That is enforced in the shape of the data itself, not by a filter. Every reseller-facing response about money is typed so that client billing details cannot be included. See Revenue and payouts.
Coming soonAn audit logs permission exists in the access model and helps open the Settings area, but there is no toggle for it in the client’s panel today, so a client cannot currently grant it. Do not plan work around it.

Not a toggle

Credentials sit outside the whole system.

The banner above the toggle list tells every client the same thing: “Your reseller can only access the scopes enabled below · Credentials are always off-limits”.

Credentials & API keys
Permanently restricted. No toggle, no exception.
HARD LIMIT
“Permanently restricted. No toggle, no exception. Your reseller can never see API keys, OAuth tokens, or service-account credentials, regardless of what’s enabled above.”

This is stronger than a permission set to off. Credentials are not a member of the permission model at all. They live in a separate restrictions list whose restricted value is a fixed constant, so there is no state the software can represent in which a reseller has credential access. Credentials and API keys walks through the four layers that enforce it.

When it takes effect

Changing a permission mid-relationship.

Client flips a toggleNothing is sent yet. The change is local until they save.
Save changesOnly the toggles that actually changed are sent, so one revoke never clears another grant.
SavedA confirmation shows for a couple of seconds, then clears.
Your next sessionScopes are resolved when a session is created, so the change lands on your next one.
You do not have to leave and come back. The Refresh permissions button in the delegated session banner picks up the current grants without losing your place. It works by creating a fresh session behind the scenes, which is why the client’s panel describes changes as taking effect on your next session.
If a client revokes a permission you were relying on, the affected area shows “Access restricted” rather than ending your session. Only an expired or deleted session ends the whole thing. See View as client.
What they see

The Manage Reseller panel, as the client sees it.

Managed Reseller
Your account is managed by
Halo Studio
Mira Santos[email protected]Certified Reseller since Mar 2026
Your reseller can only access the scopes enabled below · Credentials are always off-limits
What can your reseller access?
Prompts & Instructions
Apps and MCP
Skills
Agent Memories
Files SENSITIVE
Calendar & Schedules
Chat History SENSITIVE
Billing summary SENSITIVE
Credentials & API keys HARD LIMITalways off
Save changes
Ending it

A managed workspace stays managed.

The panel is direct about this, and you should be too when you set expectations with a prospective client. The exact wording they read is: “This workspace is permanently managed by reseller. To disconnect, you’ll need to cancel your current subscription and create a new workspace.”

What a client can do at any time
Turn any of the eight permissions off, immediately and without asking you.
Reduce you to no access at all while keeping their workspace running normally.
Contact you directly from the panel using the email shown there.
What needs more than a toggle
Detaching the workspace from your reseller account. There is no self-service button for it.
Force-disconnecting a relationship. That is an Actionist administrative action.
Granting credential access. It is not representable, by anyone, ever.
Because a client cannot detach themselves, be straightforward at the start of a relationship about what you will and will not touch. A client who understands the model tends to grant more, not less.
In practice

Ask for what the work needs.

A useful pattern is to start narrow, do visible work, and ask for more only when a specific task requires it.

Building the workspace

Prompts & Instructions, plus Apps and MCP, plus Skills. Enough to create agents, wire tools and install skill packs. Most setup work fits here.

Running it day to day

Add Calendar & Schedules so you can adjust recurring work, and Chat History if the client wants you diagnosing conversations rather than guessing.

Deep support

Add Files when you need to fix the source documents an agent reads, and Agent Memories when an agent has learned something wrong.
Agency owner
New client, first week. Asks only for Prompts & Instructions and Apps and MCP, builds three agents, and sends the client a list of the four app connections they need to authorise. Nothing sensitive requested, nothing to negotiate.
fastest path to live
Support engineer
A client reports an agent replying oddly. Asks for Chat History for the investigation, reads the transcript, corrects the instructions, and tells the client they can switch it back off.
scoped to the task
Onboarding lead
Client’s agent keeps citing an outdated price list. Asks for Files, replaces the source document, confirms the change, and summarises exactly which file was replaced.
one file, one message
Reading the room

States and controls.

A revoked permission degrades one area. It does not end your session or log you out. If you are suddenly returned to your own dashboard, that is session expiry instead, which is covered in Troubleshooting.

Permissioned by design

Access your clients can reason about.

Eight toggles they control, one restriction nobody controls, and no shared passwords anywhere in the model.

Enforced on the server, not in the interface. Revocable by the client at any moment.
Eight toggles · Three marked sensitive · Credentials outside the model entirely.

Keep going

Next steps.

View as client

How a session actually starts, what the banner tells you, and how to leave cleanly.

Credentials and API keys

The four layers that make the hard limit real, and how to hand a connection back.

Files, memories and chat history

Why three permissions cover three genuinely different stores.

Client success best practices

Setting expectations early so permission requests never feel like an imposition.