Every AI agent and automation in your business has access to something: your inbox, your diary, your customer data, maybe your bank. We give each one an identity, a job description, limits, an owner and an off switch, so you always know what your AI can do and can stop it in seconds.
Ask who has one running and you get a shrug. Zapier, Make, ChatGPT, Copilot, a voice agent…
An automation runs as the owner, or as a leaver whose account is still open.
Ordering, refunding or paying, with no limit set and nobody checking.
When something goes wrong you can't tell whether a person or the AI did it.
The person who set it up has left. It's still running.
If an agent misbehaves at 2am, who stops it, and how?
This is the joiner, mover and leaver process every well-run company has for people, applied to AI. It comes from 13 years of identity and access management.
One line per agent. Yours to keep, kept current.
| Agent | Owner | Can do | Limit | Reviewed |
|---|---|---|---|---|
| Voice agent | Office mgr | Book · transfer | No disclosure | Sep |
| Invoice chaser | Finance | Send reminders | £0 spend | Sep |
| Lead router | Sales lead | Create CRM record | Read-only email | Aug |
| Copilot (all staff) | Owner | Read · draft | No send | Sep |
| none | Refunds | none | Retired |
Illustrative example. The last line is the one most firms find.
A register for a small firm usually takes a few days. The fixes depend on what we find. You get a timeline up front.
We find every agent, bot and AI connector across your accounts, including the ones nobody remembers.
Each one scored on what it can access, what it can do, who owns it and what would happen if it went wrong.
Own identities, tight permissions, limits, approvals and off switches put in place. Nothing breaks: we test as we go.
Quarterly reviews, a register that stays current, and new agents onboarded properly before they go live.
A 30-person distributor had eleven automations and three AI assistants. Four ran under the former operations manager's login, still active six months after she left. One could issue refunds with no cap. Within two weeks every agent had its own identity, the refund agent had a limit and an approval step, and the leaver's account was finally closed.
Illustrative example, drawn from typical findings. Not a named client.
“Access control is the part most AI suppliers wave at. It's the part we came from.”
Anything that acts on your behalf without a person pressing the button each time: AI assistants with connectors (Copilot, Gemini, ChatGPT), voice agents, chatbots, Zapier, Make and n8n automations, API integrations and scheduled scripts. If it has a login, a key or a connector, it goes on the register.
If you can name them all, say what each can access and switch any one off in a minute, you're ahead of most. Most firms can't. The first step is the register, and it's usually quick. What you do next depends on what we find.
No. We change who the agent logs in as and what it's allowed to touch, not what it does. Every change is tested before the old access is removed.
Usually not. Most of this uses controls you already have in Microsoft 365, Google Workspace and your automation platforms. Where a tool would help, we'll say so, and it's your choice.
We prepare it: what each agent did, what it could access, and what changed. You approve it or ask questions. Twenty minutes, four times a year.
It depends on how many agents and systems you have. After a free discovery call we give you a fixed price for the register and the fixes, and a monthly figure if you want us to keep it reviewed.