Permissions are the access a person, system, or agent has: can it read the file, edit it, delete it, send the email? They’re how “the AI can help” becomes “the AI can help inside clear boundaries.” Reading public information is low risk; editing your CRM, deleting records, moving money, or messaging as you is not. That’s why permission scope matters: read differs from write, write from delete, draft from send.
Imagine keys in an office building. One opens the lobby, another the supply closet, another the room with client files, another the server closet. You wouldn’t give everyone every key just because they’re helpful.
Why you care
The tempting shortcut is “just skip the prompts.” Experienced operators sometimes run broad access inside a controlled sandbox, but broad access is broad access; the word “dangerous” is in dangerous permission skip for a reason. For everyday client work, give the agent the least access that still does the job: let it draft freely, read when it’s low-risk, and require approval before it sends, deletes, overwrites, or changes systems of record.