> ## Documentation Index
> Fetch the complete documentation index at: https://learn.actionist.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Client permissions and access

> Eight toggles the client owns, one restriction nobody can lift, and exactly what each permission unlocks inside their workspace.

<div className="mxp-hero xc-border">
  <div className="exp-eyebrow mxp-rise">THE CLIENT HOLDS THE DIAL</div>

  <h2 className="mxp-hero-title mxp-rise" style={{animationDelay:'0.06s'}}>
    Eight toggles they own. <span style={{background:'linear-gradient(90deg,#24A4FF,#9000FF,#E3008E)',WebkitBackgroundClip:'text',backgroundClip:'text',color:'transparent'}}>One line nobody crosses.</span>
  </h2>

  <p className="mxp-hero-dek mxp-rise" style={{animationDelay:'0.13s'}}>
    Every client decides what their reseller can see and change, toggle by toggle, and can change their mind at any time. Credentials are not on the list, because credentials are never on the list.
  </p>
</div>

<div className="w-full py-10">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">For the client</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">The Manage Reseller panel.</h2>

    <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
      When a workspace is managed by a reseller, a **Manage Reseller** item appears in the client's Reseller sub-navigation. That panel is where all of this is decided.
    </p>
  </div>

  <div className="exp-surface-grid" style={{marginTop:'22px'}}>
    <div className="exp-surface-tile">
      <strong>They see who you are.</strong> The panel shows your company name, your contact person, a clickable email address, and the month you were certified.
    </div>

    <div className="exp-surface-tile">
      <strong>They set the scope.</strong> Eight toggles, three of them marked SENSITIVE. Nothing is granted by assumption.
    </div>

    <div className="exp-surface-tile">
      <strong>They can change it whenever.</strong> Saving sends only the toggles that actually changed, so flipping one off never quietly resets another.
    </div>
  </div>

  <Info>
    A client who is not managed by anyone sees a single line instead: "Your workspace is not currently managed by a reseller." If a client tells you the panel is missing, that is usually because the relationship has not finished attaching yet. See [Onboarding a new client](/resellers/client-onboarding).
  </Info>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">Try it</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">What each toggle actually unlocks.</h2>

    <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
      Permissions are abstract until you see them as doors. Switch the toggles below to watch a client workspace open up. This is the real mapping the app uses.
    </p>
  </div>

  <div className="xrs-nm exp-tool-shell xc-try">
    <div style={{fontSize:11.5, opacity:0.55, letterSpacing:'0.07em', textTransform:'uppercase', fontWeight:600, marginBottom:10}}>Grant a permission, see what opens</div>

    <div className="mxp-srch-chips">
      <label htmlFor="xp-prompts"><input className="mxp-r" type="checkbox" id="xp-prompts" defaultChecked />Prompts & Instructions</label>
      <label htmlFor="xp-tools"><input className="mxp-r" type="checkbox" id="xp-tools" defaultChecked />Apps and MCP</label>
      <label htmlFor="xp-skills"><input className="mxp-r" type="checkbox" id="xp-skills" />Skills</label>
      <label htmlFor="xp-memory"><input className="mxp-r" type="checkbox" id="xp-memory" />Agent Memories</label>
      <label htmlFor="xp-files"><input className="mxp-r" type="checkbox" id="xp-files" />Files</label>
      <label htmlFor="xp-calendar"><input className="mxp-r" type="checkbox" id="xp-calendar" />Calendar & Schedules</label>
      <label htmlFor="xp-chats"><input className="mxp-r" type="checkbox" id="xp-chats" />Chat History</label>
      <label htmlFor="xp-billing"><input className="mxp-r" type="checkbox" id="xp-billing" />Billing summary</label>
    </div>

    <div className="xrs-nm-grid">
      <div className="xrs-nm-item nm-home"><i />Home</div>
      <div className="xrs-nm-item nm-agents"><i />Agents</div>
      <div className="xrs-nm-item nm-onboarding"><i />Onboarding</div>
      <div className="xrs-nm-item nm-impact"><i />Impact</div>
      <div className="xrs-nm-item nm-apps"><i />Apps</div>
      <div className="xrs-nm-item nm-skills"><i />Skills</div>
      <div className="xrs-nm-item nm-memory"><i />Memory</div>
      <div className="xrs-nm-item nm-files"><i />Files</div>
      <div className="xrs-nm-item nm-calendar"><i />Calendar</div>
      <div className="xrs-nm-item nm-settings"><i />Settings</div>
      <div className="xrs-nm-item always"><i />Marketplace</div>
      <div className="xrs-nm-item always"><i />Learn</div>
      <div className="xrs-nm-item always"><i />Support</div>
      <div className="xrs-nm-item never"><i />Reseller</div>
      <div className="xrs-nm-item never"><i />Projects</div>
    </div>

    <div className="xrs-nm-note">
      <svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2.2" strokeLinecap="round" strokeLinejoin="round">
        <circle cx="12" cy="12" r="10" />

        <line x1="12" y1="8" x2="12" y2="12" />

        <line x1="12" y1="16" x2="12.01" y2="16" />
      </svg>

      Chat History without Prompts & Instructions opens Home in view-only mode. You can read the conversation history, but the composer stays disabled.
    </div>

    <div style={{display:'flex', alignItems:'center', gap:16, marginTop:16, flexWrap:'wrap', fontSize:12, opacity:0.65}}>
      <span style={{display:'flex', alignItems:'center', gap:6}}><span style={{width:8,height:8,borderRadius:999,background:'#6EE3B5',display:'inline-block'}} /> Always open, no permission needed</span>
      <span style={{display:'flex', alignItems:'center', gap:6}}><span style={{width:8,height:8,borderRadius:999,background:'#f06060',display:'inline-block'}} /> Always locked, whatever is granted</span>
    </div>
  </div>

  <Note>
    Two areas are locked in every delegated session regardless of what the client grants: the **Reseller** section itself, and **Projects**. You cannot use a client's workspace to manage your own reseller account, and the planning surface has no delegated permission defined yet.
  </Note>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">The list</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">Eight permissions, in the order the client sees them.</h2>

    <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
      Three carry a SENSITIVE marker. That marker is a prompt to think, not a block, and the client can still grant them.
    </p>
  </div>

  <div className="xrs-scope-table">
    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Prompts & Instructions</div>
        <div className="xrs-scope-desc">Edit agent configuration, including system prompts and instructions on this workspace's agents.</div>
      </div>

      <span className="xrs-scope-on">On</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Apps and MCP</div>
        <div className="xrs-scope-desc">Manage the Apps section, including tools, MCP servers, and connections that do not require credentials.</div>
      </div>

      <span className="xrs-scope-on">On</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Skills</div>
        <div className="xrs-scope-desc">Install, enable, disable, or remove skills.</div>
      </div>

      <span className="xrs-scope-on">On</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Agent Memories</div>
        <div className="xrs-scope-desc">View and modify what agents learned while working, including memories formed during customer interactions.</div>
      </div>

      <span className="xrs-scope-off">Off</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Files <span className="xrs-sens">SENSITIVE</span></div>
        <div className="xrs-scope-desc">Audit, replace, or remove proprietary documents, PDFs, and datasets the agents reference.</div>
      </div>

      <span className="xrs-scope-off">Off</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Calendar & Schedules</div>
        <div className="xrs-scope-desc">View and edit scheduled agent runs, recurring jobs, and calendar-connected workflows.</div>
      </div>

      <span className="xrs-scope-on">On</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Chat History <span className="xrs-sens">SENSITIVE</span></div>
        <div className="xrs-scope-desc">Read the full conversation history between the client's team and their agents.</div>
      </div>

      <span className="xrs-scope-off">Off</span>
    </div>

    <div className="xrs-scope-row">
      <div>
        <div className="xrs-scope-name">Billing summary <span className="xrs-sens">SENSITIVE</span></div>
        <div className="xrs-scope-desc">View aggregate plan usage. Card details and invoice documents are never included.</div>
      </div>

      <span className="xrs-scope-off">Off</span>
    </div>

    <div className="xrs-scope-row" style={{borderTop:'1px solid rgb(255 72 72 / 0.25)', background:'rgb(255 72 72 / 0.03)'}}>
      <div>
        <div className="xrs-scope-name">Credentials & API keys <span className="xrs-hard-limit-badge">HARD LIMIT</span></div>
        <div className="xrs-scope-desc">Server-enforced permanent restriction. There is no toggle for this row.</div>
      </div>

      <span style={{fontSize:11, opacity:0.4, fontFamily:'"JetBrains Mono",monospace'}}>always off</span>
    </div>
  </div>

  <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl" style={{marginTop:'20px'}}>
    The exact wording each client reads is longer than the summaries above. Two are worth quoting in full, because they draw lines that surprise people.
  </p>

  <AccordionGroup>
    <Accordion title="Apps and MCP, in the client's own words" icon="plug" defaultOpen={true}>
      "Manage the Apps section, including tools, MCP servers, and app connections that don't require credentials. Installing credential-based apps, connecting OAuth apps, and disabling or modifying anything tied to API keys, OAuth tokens, or other secrets is always off-limits, regardless of this setting."

      Read that last clause carefully. Granting this permission does not let you finish a connection that needs a login. Nothing does. See [Apps, tools and integrations](/resellers/apps).
    </Accordion>

    <Accordion title="Files versus Agent Memories" icon="folder-open">
      Files: "Audit, replace, or remove proprietary documents, PDFs, and datasets your agents reference. Distinct from Memories, Files are the static source assets you uploaded."

      Agent Memories: "View and modify ephemeral agent state, including memories formed during customer interactions."

      They are genuinely different stores with different permissions. [Files, memories and chat history](/resellers/files-and-memory) explains why granting one does not imply the other, and why the Agent Memories permission does not open a memory editor.
    </Accordion>

    <Accordion title="Billing summary" icon="credit-card">
      "View aggregate plan usage. They never see your credit card or invoice PDFs."

      That is enforced in the shape of the data itself, not by a filter. Every reseller-facing response about money is typed so that client billing details cannot be included. See [Revenue and payouts](/resellers/revenue).
    </Accordion>

    <Accordion title="Audit Logs" icon="scroll-text">
      <Badge color="purple" size="sm">Coming soon</Badge>

      An audit logs permission exists in the access model and helps open the Settings area, but there is no toggle for it in the client's panel today, so a client cannot currently grant it. Do not plan work around it.
    </Accordion>
  </AccordionGroup>
</div>

<hr className="xc-divider" />

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">Not a toggle</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">Credentials sit outside the whole system.</h2>

    <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
      The banner above the toggle list tells every client the same thing: "Your reseller can only access the scopes enabled below · Credentials are always off-limits".
    </p>
  </div>

  <div className="xrs-hard-limit-row" style={{marginTop:0}}>
    <div>
      <div style={{fontWeight:600, fontSize:13}}>Credentials & API keys</div>
      <div style={{fontSize:12, opacity:0.7}}>Permanently restricted. No toggle, no exception.</div>
    </div>

    <span className="xrs-hard-limit-badge">HARD LIMIT</span>
  </div>

  <Danger>
    "Permanently restricted. No toggle, no exception. Your reseller can never see API keys, OAuth tokens, or service-account credentials, regardless of what's enabled above."
  </Danger>

  <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl" style={{marginTop:'18px'}}>
    This is stronger than a permission set to off. Credentials are not a member of the permission model at all. They live in a separate restrictions list whose restricted value is a fixed constant, so there is no state the software can represent in which a reseller has credential access. [Credentials and API keys](/resellers/credentials) walks through the four layers that enforce it.
  </p>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">When it takes effect</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">Changing a permission mid-relationship.</h2>
  </div>

  <div className="mxp-pipe">
    <div className="mxp-pipe-node"><strong>Client flips a toggle</strong><span>Nothing is sent yet. The change is local until they save.</span></div>

    <div className="mxp-pipe-link" />

    <div className="mxp-pipe-node"><strong>Save changes</strong><span>Only the toggles that actually changed are sent, so one revoke never clears another grant.</span></div>

    <div className="mxp-pipe-link d2" />

    <div className="mxp-pipe-node"><strong>Saved</strong><span>A confirmation shows for a couple of seconds, then clears.</span></div>

    <div className="mxp-pipe-link d3" />

    <div className="mxp-pipe-node"><strong>Your next session</strong><span>Scopes are resolved when a session is created, so the change lands on your next one.</span></div>
  </div>

  <Tip>
    You do not have to leave and come back. The **Refresh permissions** button in the delegated session banner picks up the current grants without losing your place. It works by creating a fresh session behind the scenes, which is why the client's panel describes changes as taking effect on your next session.
  </Tip>

  <Warning>
    If a client revokes a permission you were relying on, the affected area shows "Access restricted" rather than ending your session. Only an expired or deleted session ends the whole thing. See [View as client](/resellers/view-as-client).
  </Warning>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">What they see</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">The Manage Reseller panel, as the client sees it.</h2>
  </div>

  <div className="mxp-window xrs-mock-window">
    <div className="mxp-window-bar xrs-mock-titlebar">
      <span className="mxp-window-dot xrs-mock-dot red" />

      <span className="mxp-window-dot xrs-mock-dot yel" />

      <span className="mxp-window-dot xrs-mock-dot grn" />

      <span className="mxp-window-title">Managed Reseller</span>
    </div>

    <div className="xrs-mock-body">
      <div className="xrs-mock-reseller-info">
        <div style={{fontSize:11, letterSpacing:'0.07em', textTransform:'uppercase', opacity:0.5, marginBottom:6}}>Your account is managed by</div>
        <div style={{fontSize:14,fontWeight:700,marginBottom:6}}>Halo Studio</div>

        <div style={{display:'flex',flexWrap:'wrap',gap:12,fontSize:11.5,opacity:0.6}}>
          <span>Mira Santos</span>
          <span style={{color:'rgb(var(--actionist-purple-bright))'}}>[contact@halo.studio](mailto:contact@halo.studio)</span>
          <span>Certified Reseller since Mar 2026</span>
        </div>
      </div>

      <div style={{display:'flex',alignItems:'center',gap:8,padding:'9px 14px',borderRadius:8,fontSize:11.5,border:'1px solid rgb(144 0 255 / 0.25)',background:'rgb(144 0 255 / 0.05)',opacity:0.85,marginBottom:14}}>
        <svg width="13" height="13" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2.2" strokeLinecap="round" strokeLinejoin="round">
          <circle cx="12" cy="12" r="10" />

          <line x1="12" y1="8" x2="12" y2="12" />

          <line x1="12" y1="16" x2="12.01" y2="16" />
        </svg>

        Your reseller can only access the scopes enabled below · Credentials are always off-limits
      </div>

      <div style={{fontSize:11, letterSpacing:'0.07em', textTransform:'uppercase', opacity:0.5, marginBottom:8}}>What can your reseller access?</div>
      <div className="xrs-mock-toggle-row"><span>Prompts & Instructions</span><span className="xrs-mock-toggle on" /></div>
      <div className="xrs-mock-toggle-row"><span>Apps and MCP</span><span className="xrs-mock-toggle on" /></div>
      <div className="xrs-mock-toggle-row"><span>Skills</span><span className="xrs-mock-toggle on" /></div>
      <div className="xrs-mock-toggle-row"><span>Agent Memories</span><span className="xrs-mock-toggle off" /></div>
      <div className="xrs-mock-toggle-row"><span>Files <span className="xrs-sens">SENSITIVE</span></span><span className="xrs-mock-toggle off" /></div>
      <div className="xrs-mock-toggle-row"><span>Calendar & Schedules</span><span className="xrs-mock-toggle on" /></div>
      <div className="xrs-mock-toggle-row"><span>Chat History <span className="xrs-sens">SENSITIVE</span></span><span className="xrs-mock-toggle off" /></div>
      <div className="xrs-mock-toggle-row"><span>Billing summary <span className="xrs-sens">SENSITIVE</span></span><span className="xrs-mock-toggle off" /></div>

      <div className="xrs-mock-toggle-row" style={{borderTop:'1px solid rgb(255 72 72 / 0.25)', background:'rgb(255 72 72 / 0.03)', padding:'9px 8px', borderRadius:8, marginTop:6, borderBottom:'none'}}>
        <span style={{display:'flex', alignItems:'center', gap:8}}>
          Credentials & API keys
          <span className="xrs-hard-limit-badge">HARD LIMIT</span>
        </span>

        <span style={{fontSize:11, opacity:0.4, fontFamily:'"JetBrains Mono",monospace'}}>always off</span>
      </div>

      <div style={{marginTop:16}}><span className="xrs-mock-cta">Save changes</span></div>
    </div>
  </div>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">Ending it</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">A managed workspace stays managed.</h2>
  </div>

  <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
    The panel is direct about this, and you should be too when you set expectations with a prospective client. The exact wording they read is: "This workspace is permanently managed by {'{'}reseller{'}'}. To disconnect, you'll need to cancel your current subscription and create a new workspace."
  </p>

  <div className="xrs-two">
    <div className="xrs-two-col can">
      <div className="xrs-two-tag">What a client can do at any time</div>
      <div className="xrs-two-item">Turn any of the eight permissions off, immediately and without asking you.</div>
      <div className="xrs-two-item">Reduce you to no access at all while keeping their workspace running normally.</div>
      <div className="xrs-two-item">Contact you directly from the panel using the email shown there.</div>
    </div>

    <div className="xrs-two-col cant">
      <div className="xrs-two-tag">What needs more than a toggle</div>
      <div className="xrs-two-item">Detaching the workspace from your reseller account. There is no self-service button for it.</div>
      <div className="xrs-two-item">Force-disconnecting a relationship. That is an Actionist administrative action.</div>
      <div className="xrs-two-item">Granting credential access. It is not representable, by anyone, ever.</div>
    </div>
  </div>

  <Note>
    Because a client cannot detach themselves, be straightforward at the start of a relationship about what you will and will not touch. A client who understands the model tends to grant more, not less.
  </Note>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">In practice</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">Ask for what the work needs.</h2>

    <p className="text-base text-gray-600 dark:text-gray-400 max-w-3xl">
      A useful pattern is to start narrow, do visible work, and ask for more only when a specific task requires it.
    </p>
  </div>

  <Columns cols={3}>
    <Card title="Building the workspace" icon="hammer">
      Prompts & Instructions, plus Apps and MCP, plus Skills. Enough to create agents, wire tools and install skill packs. Most setup work fits here.
    </Card>

    <Card title="Running it day to day" icon="calendar-clock">
      Add Calendar & Schedules so you can adjust recurring work, and Chat History if the client wants you diagnosing conversations rather than guessing.
    </Card>

    <Card title="Deep support" icon="search">
      Add Files when you need to fix the source documents an agent reads, and Agent Memories when an agent has learned something wrong.
    </Card>
  </Columns>

  <div className="xc-recipes" style={{marginTop:'22px'}}>
    <div className="xc-recipe">
      <div className="xc-recipe-who">
        <i style={{background:'linear-gradient(135deg,#9000FF,#00DBFF)'}} />

        Agency owner
      </div>

      <div className="xc-recipe-flow">
        New client, first week. Asks only for <em>Prompts & Instructions</em> and <em>Apps and MCP</em>, builds three agents, and sends the client a list of the four app connections they need to authorise. Nothing sensitive requested, nothing to negotiate.
      </div>

      <span className="xc-recipe-save">fastest path to live</span>
    </div>

    <div className="xc-recipe">
      <div className="xc-recipe-who">
        <i style={{background:'linear-gradient(135deg,#9000FF,#00DBFF)'}} />

        Support engineer
      </div>

      <div className="xc-recipe-flow">
        A client reports an agent replying oddly. Asks for <em>Chat History</em> for the investigation, reads the transcript, corrects the instructions, and tells the client they can switch it back off.
      </div>

      <span className="xc-recipe-save">scoped to the task</span>
    </div>

    <div className="xc-recipe">
      <div className="xc-recipe-who">
        <i style={{background:'linear-gradient(135deg,#9000FF,#00DBFF)'}} />

        Onboarding lead
      </div>

      <div className="xc-recipe-flow">
        Client's agent keeps citing an outdated price list. Asks for <em>Files</em>, replaces the source document, confirms the change, and summarises exactly which file was replaced.
      </div>

      <span className="xc-recipe-save">one file, one message</span>
    </div>
  </div>
</div>

<div className="w-full py-10 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">Reading the room</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">States and controls.</h2>
  </div>

  | What you see                                                   | Why                                                                                  | What to do next                                                                                 |
  | -------------------------------------------------------------- | ------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------- |
  | A section shows "Access restricted"                            | The client has not granted that permission, or revoked it since your session started | Click **Refresh permissions** in the banner. If it is still locked, ask the client to enable it |
  | "This page is not available while viewing a client workspace." | The Reseller or Projects area, which no permission unlocks                           | Nothing. Exit the session to reach your own reseller dashboard                                  |
  | Home loads but you cannot type a message                       | Chat History is granted, Prompts & Instructions is not                               | Ask for Prompts & Instructions if you need to run the agent, not just read it                   |
  | An app's Connect button is greyed out with a lock              | Always the case in a delegated session, whatever is granted                          | Ask the client to connect that app themselves. See [Apps](/resellers/apps)                      |
  | A client says the Manage Reseller panel is missing             | Their workspace has not finished attaching yet                                       | Check the Clients table. See [Onboarding a new client](/resellers/client-onboarding)            |

  <Note>
    A revoked permission degrades one area. It does not end your session or log you out. If you are suddenly returned to your own dashboard, that is session expiry instead, which is covered in [Troubleshooting](/resellers/troubleshooting).
  </Note>
</div>

<hr className="xc-divider" />

<div className="w-full py-10">
  <div className="actionist-cta-panel xc-border">
    <div className="relative z-10 flex flex-col items-center gap-5 max-w-2xl mx-auto">
      <span className="actionist-eyebrow">Permissioned by design</span>

      <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-white leading-tight">
        Access your clients can reason about.
      </h2>

      <p className="text-base md:text-lg text-white/85">
        Eight toggles they control, one restriction nobody controls, and no shared passwords anywhere in the model.
      </p>

      <div className="flex flex-wrap items-center justify-center gap-3 pt-2">
        <a className="actionist-cta-btn-primary" href="https://app.actionist.ai" target="_blank" rel="noreferrer">
          Open the Dashboard

          <svg width="14" height="14" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2.2" strokeLinecap="round" strokeLinejoin="round">
            <path d="M5 12h14" />

            <path d="m12 5 7 7-7 7" />
          </svg>
        </a>

        <a className="actionist-cta-btn-secondary" href="https://actionist.ai/partners/" target="_blank" rel="noreferrer">
          Signup as a Partner
        </a>
      </div>
    </div>
  </div>
</div>

<div className="w-full pt-2 pb-6">
  <p className="actionist-trust-line">
    Enforced on the server, not in the interface. Revocable by the client at any moment.<br />
    Eight toggles · Three marked sensitive · Credentials outside the model entirely.
  </p>
</div>

<div className="w-full pb-16 xc-rise">
  <div className="actionist-tight flex flex-col gap-2 mb-6">
    <span className="actionist-section-eyebrow">Keep going</span>
    <h2 className="text-2xl md:text-3xl font-semibold tracking-tight text-gray-900 dark:text-gray-50">Next steps.</h2>
  </div>

  <Columns cols={4}>
    <Card title="View as client" icon="log-in" href="/resellers/view-as-client">
      How a session actually starts, what the banner tells you, and how to leave cleanly.
    </Card>

    <Card title="Credentials and API keys" icon="key" href="/resellers/credentials">
      The four layers that make the hard limit real, and how to hand a connection back.
    </Card>

    <Card title="Files, memories and chat history" icon="folder-open" href="/resellers/files-and-memory">
      Why three permissions cover three genuinely different stores.
    </Card>

    <Card title="Client success best practices" icon="badge-check" href="/resellers/best-practices">
      Setting expectations early so permission requests never feel like an imposition.
    </Card>
  </Columns>
</div>
