Every client decides what their reseller can see and change, toggle by toggle, and can change their mind at any time. Credentials are not on the list, because credentials are never on the list.
When a workspace is managed by a reseller, a Manage Reseller item appears in the client’s Reseller sub-navigation. That panel is where all of this is decided.
They see who you are. The panel shows your company name, your contact person, a clickable email address, and the month you were certified.
They set the scope. Eight toggles, three of them marked SENSITIVE. Nothing is granted by assumption.
They can change it whenever. Saving sends only the toggles that actually changed, so flipping one off never quietly resets another.
A client who is not managed by anyone sees a single line instead: “Your workspace is not currently managed by a reseller.” If a client tells you the panel is missing, that is usually because the relationship has not finished attaching yet. See Onboarding a new client.
Permissions are abstract until you see them as doors. Switch the toggles below to watch a client workspace open up. This is the real mapping the app uses.
Grant a permission, see what opens
Home
Agents
Onboarding
Impact
Apps
Skills
Memory
Files
Calendar
Settings
Marketplace
Learn
Support
Reseller
Projects
Chat History without Prompts & Instructions opens Home in view-only mode. You can read the conversation history, but the composer stays disabled.
Always open, no permission needed Always locked, whatever is granted
Two areas are locked in every delegated session regardless of what the client grants: the Reseller section itself, and Projects. You cannot use a client’s workspace to manage your own reseller account, and the planning surface has no delegated permission defined yet.
Eight permissions, in the order the client sees them.
Three carry a SENSITIVE marker. That marker is a prompt to think, not a block, and the client can still grant them.
Prompts & Instructions
Edit agent configuration, including system prompts and instructions on this workspace’s agents.
On
Apps and MCP
Manage the Apps section, including tools, MCP servers, and connections that do not require credentials.
On
Skills
Install, enable, disable, or remove skills.
On
Agent Memories
View and modify what agents learned while working, including memories formed during customer interactions.
Off
Files SENSITIVE
Audit, replace, or remove proprietary documents, PDFs, and datasets the agents reference.
Off
Calendar & Schedules
View and edit scheduled agent runs, recurring jobs, and calendar-connected workflows.
On
Chat History SENSITIVE
Read the full conversation history between the client’s team and their agents.
Off
Billing summary SENSITIVE
View aggregate plan usage. Card details and invoice documents are never included.
Off
Credentials & API keys HARD LIMIT
Server-enforced permanent restriction. There is no toggle for this row.
always off
The exact wording each client reads is longer than the summaries above. Two are worth quoting in full, because they draw lines that surprise people.
Apps and MCP, in the client's own words
“Manage the Apps section, including tools, MCP servers, and app connections that don’t require credentials. Installing credential-based apps, connecting OAuth apps, and disabling or modifying anything tied to API keys, OAuth tokens, or other secrets is always off-limits, regardless of this setting.”Read that last clause carefully. Granting this permission does not let you finish a connection that needs a login. Nothing does. See Apps, tools and integrations.
Files versus Agent Memories
Files: “Audit, replace, or remove proprietary documents, PDFs, and datasets your agents reference. Distinct from Memories, Files are the static source assets you uploaded.”Agent Memories: “View and modify ephemeral agent state, including memories formed during customer interactions.”They are genuinely different stores with different permissions. Files, memories and chat history explains why granting one does not imply the other, and why the Agent Memories permission does not open a memory editor.
Billing summary
“View aggregate plan usage. They never see your credit card or invoice PDFs.”That is enforced in the shape of the data itself, not by a filter. Every reseller-facing response about money is typed so that client billing details cannot be included. See Revenue and payouts.
Audit Logs
Coming soonAn audit logs permission exists in the access model and helps open the Settings area, but there is no toggle for it in the client’s panel today, so a client cannot currently grant it. Do not plan work around it.
The banner above the toggle list tells every client the same thing: “Your reseller can only access the scopes enabled below · Credentials are always off-limits”.
Credentials & API keys
Permanently restricted. No toggle, no exception.
HARD LIMIT
“Permanently restricted. No toggle, no exception. Your reseller can never see API keys, OAuth tokens, or service-account credentials, regardless of what’s enabled above.”
This is stronger than a permission set to off. Credentials are not a member of the permission model at all. They live in a separate restrictions list whose restricted value is a fixed constant, so there is no state the software can represent in which a reseller has credential access. Credentials and API keys walks through the four layers that enforce it.
Client flips a toggleNothing is sent yet. The change is local until they save.
Save changesOnly the toggles that actually changed are sent, so one revoke never clears another grant.
SavedA confirmation shows for a couple of seconds, then clears.
Your next sessionScopes are resolved when a session is created, so the change lands on your next one.
You do not have to leave and come back. The Refresh permissions button in the delegated session banner picks up the current grants without losing your place. It works by creating a fresh session behind the scenes, which is why the client’s panel describes changes as taking effect on your next session.
If a client revokes a permission you were relying on, the affected area shows “Access restricted” rather than ending your session. Only an expired or deleted session ends the whole thing. See View as client.
The panel is direct about this, and you should be too when you set expectations with a prospective client. The exact wording they read is: “This workspace is permanently managed by reseller. To disconnect, you’ll need to cancel your current subscription and create a new workspace.”
What a client can do at any time
Turn any of the eight permissions off, immediately and without asking you.
Reduce you to no access at all while keeping their workspace running normally.
Contact you directly from the panel using the email shown there.
What needs more than a toggle
Detaching the workspace from your reseller account. There is no self-service button for it.
Force-disconnecting a relationship. That is an Actionist administrative action.
Granting credential access. It is not representable, by anyone, ever.
Because a client cannot detach themselves, be straightforward at the start of a relationship about what you will and will not touch. A client who understands the model tends to grant more, not less.
A useful pattern is to start narrow, do visible work, and ask for more only when a specific task requires it.
Building the workspace
Prompts & Instructions, plus Apps and MCP, plus Skills. Enough to create agents, wire tools and install skill packs. Most setup work fits here.
Running it day to day
Add Calendar & Schedules so you can adjust recurring work, and Chat History if the client wants you diagnosing conversations rather than guessing.
Deep support
Add Files when you need to fix the source documents an agent reads, and Agent Memories when an agent has learned something wrong.
Agency owner
New client, first week. Asks only for Prompts & Instructions and Apps and MCP, builds three agents, and sends the client a list of the four app connections they need to authorise. Nothing sensitive requested, nothing to negotiate.
fastest path to live
Support engineer
A client reports an agent replying oddly. Asks for Chat History for the investigation, reads the transcript, corrects the instructions, and tells the client they can switch it back off.
scoped to the task
Onboarding lead
Client’s agent keeps citing an outdated price list. Asks for Files, replaces the source document, confirms the change, and summarises exactly which file was replaced.
A revoked permission degrades one area. It does not end your session or log you out. If you are suddenly returned to your own dashboard, that is session expiry instead, which is covered in Troubleshooting.
Enforced on the server, not in the interface. Revocable by the client at any moment.
Eight toggles · Three marked sensitive · Credentials outside the model entirely.