ai estate-agent-software mcp permissions workshop-report
We asked the assistant which websites it could see. The answer was two, our own and the one of a pilot customer. A few minutes later, the same question and the same function, and the answer was one.
Nothing had been deleted. Between the two calls the estate agent software had changed the user the assistant works under. Before it was an account with administrator rights, afterwards an account of its own for the AI. And that account is not allowed to see the second website.
The AI is a user, not an access key
In most systems an AI hangs on a key. The key belongs to nobody, it may do everything the interface offers, and anyone who wants to know what happened with it reads log files.
With us it is a user account like any other. It has a login name, a role, a group and the same permissions as a person at a workstation. It is explicitly not a system administrator. What this account may not see, the AI does not get to see, and not because the interface filters it out, but because the request is checked in the same place as every other one.
That is why the second website was gone. Not locked, not hidden, simply not in the answer.
Why that is the difference
A key that may do everything can only be withdrawn as a whole. A user account can be adjusted, the way you would for a new member of staff. You give the AI access to the properties but not to the invoicing. You take a group away from it, and the matter is settled on the next call. Nobody has to change the interface, nobody has to ship a new release.
If you ever want to check what the AI is actually allowed to do, you do not look into a configuration file. You look into the user administration, where it stands next to the people.
The permission model was there before
Nothing was invented here. Access rights sit on the record and are inherited by everything below it, and the search dialogue shows each person only the results they are allowed to see. We have described both of those here already.
The AI is simply the next case of the same rule. That was exactly the point. A permission model that needs an exception for an AI is not one.
The assistant has an inbox as well
Because the account is a user, it has everything a user has, including an inbox. Server notifications, messages from colleagues and assignments arrive there, each with a subject and a severity. A machine-readable attachment can travel with every message, so that a matter does not fall apart into prose when a machine picks it up.
The previous post on this blog came about exactly this way. It arrived as a message in the inbox, and the recipient wrote it.
What this means for you
Anyone letting an AI near their property data rarely asks how clever it is. They ask what it is allowed to do. With us there is an answer to that which can be looked up, and it sits in the same place as the answer for every member of staff.