Skip to content

Managing AI Access

You decide who can use VMXpert and what it's allowed to do. All of this is controlled from one page:

Admin → Toolbox → VMXpert → AI Capabilities

This page is only visible to administrators with AI management access.

Turning VMXpert on or off per person

The simplest control is the master switch at the top of each employee's editor:

  • On — the employee can use VMXpert.
  • Off — the employee doesn't get VMXpert at all. The assistant won't appear for them.
  • Inherit — the employee follows their group's setting (or the default, if the group hasn't set one).

To restrict access to just managers, for example: set the managers' group On, set the everyone-else group Off, and leave individual employees on Inherit. New hires then get the right access automatically based on their group.

Fine-grained capabilities

Beyond the on/off switch, each employee or group has a list of capabilities. Each one can be set to:

  • Allow — VMXpert can use it freely.
  • Approve — VMXpert can use it, but each action pauses for a human OK first — the request lands in the Tool Approvals queue (and appears inline for the person chatting). Good for things like outside email or data changes, where you want a person in the loop.
  • Deny — VMXpert can't use it for this person at all.
  • Inherit / Unset — falls through to the group's setting, then to the safe default.

You can browse these by person, by group, or flip to the By capability tab to see one capability across everyone at once — handy for questions like "who can send outside email?"

What the capabilities mean

  • database — look up your live POS data (sales, inventory, customers).
  • writes — propose changes to POS data and attach files. Changes are always reviewed before applying, whatever this is set to — see Making Changes.
  • email — governs email to outside addresses only; emailing your own staff is always allowed. Deny = outside email refused · Approve = each outside email is a draft the person confirms · Allow = sends directly.
  • documents — read uploaded PDFs, photos, and scanned files; transcribe audio.
  • knowledge — search your uploaded knowledge files (handbooks, policies, SOPs). See Knowledge Files.
  • web — search and fetch pages from the public internet.
  • quickbooks — read your QuickBooks books and re-push existing VMX records to them.
  • images — generate images (signs, mockups, social graphics).
  • automation — create and manage routines, workflows, and agents.
  • scripting — run computed data transforms and background helpers.
  • consult — hand work to another agent.
  • effort_deep — access to the Deep effort level (the most careful, most expensive thinking tier).

Agents and routines

If you use VMXpert agents or scheduled routines, they have their own capability settings on the same page. The rule to remember: an agent can never exceed its owner. Its effective permissions are the overlap of its own settings and its owner's — you can make an agent more restricted than the person who owns it, never less. (Judgment-style routines are governed through the agent that carries them out, which is why they point you to the Agents tab.)

Controlling spending

Access control is one lever; the other is budgets. You can give each employee (and each agent) a monthly credit cap so nobody can burn through your balance — see AI Credits & Budgets.

Tip

Not sure how to set this up for your team? Reach out to us for help anytime!