“The agent can only touch what you allow” is easy to say. Here is the specific shape of it.
Every agent product claims to be scoped. The claims differ enormously once you ask what the unit of scope actually is.
Per person, not per company
Rowbot's allow-list belongs to a person, not to a tenant. Finance's agent sees finance's sites. Sales's agent sees sales's. An admin grants a site to someone specifically, and revokes it the same way.
That matters because company-level scope collapses under its own convenience: the list only ever grows, and eventually it is the union of everything anyone needed once.
Deny by default
Anything not on the list is blocked. Not warned about, not logged and allowed — blocked. An agent that can navigate somewhere unapproved is one confused step away from acting there.
Sign-off stays with a person
Scope decides where the agent can go. Approval decides what becomes real. Anything that changes data waits for a person, which means the worst case for a bad rule is a queue you reject rather than a cleanup you run.
← All posts