Who Can See What
This page is the VMXpert privacy and permissions model in one place: what the AI can change, what your team can look up, who can read whose conversations, and where the hard limits are. Each section links the page that controls it.
Changes to your data: proposed, checked, then applied
VMXpert never edits your data directly. Every change — a purchase order update, an item edit, a price change — is a proposal that a person approves, and the approval is checked against that person's real VMX permissions before anything is applied. Someone without permission to edit inventory cannot approve an inventory change, no matter what they ask the assistant to do. The AI cannot talk its way past the permission system.
See Making Changes for how proposals and approvals work, and Approvals for where pending ones wait.
Questions: what a chat user can look up
Anyone you've given chat access can ask about the business data the assistant works from — sales, inventory, customers, purchasing. Chat access is a real decision: if someone shouldn't see sales totals, don't turn chat on for them, or use the per-capability settings under AI Access to limit what they can do. Read-side limits inside a chat are coarser than VMX's page-by-page permissions today — we say that plainly rather than imply otherwise.
See Managing AI Access for turning VMXpert on or off per person or per group.
Conversations: private to each person, auditable by owners
Each person's chats are their own — coworkers can't open them. Owners and admins can read every conversation under Chat Activity, including who asked what and the full exchange. That cuts both ways on purpose: your team should know chats are auditable, and you should know you can audit them.
Pages: the link is the key
A page VMXpert builds for you (a dashboard, a form, a leaderboard) is visible to anyone who has its link. There is no per-person permission on a page today. Treat links like keys: share a numbers-heavy dashboard the same way you'd share the numbers themselves, and keep those links inside the business.
Outbound email: a person approves every send
Only people you've named can trigger email to anyone outside the business, and each send waits for that person's approval. Agents can only write to addresses on their own allow list. Nothing leaves the building on the assistant's say-so alone.
See Emailing VMXpert for the trust rules on inbound and outbound mail.
Knowledge files: internal unless you say otherwise
Documents you upload (handbooks, SOPs, policies) inform the assistant's answers for your team. Anything customer-facing draws only on what you'd say across the counter — internal detail like PTO policy stays internal.
See Knowledge Files for what to upload and how it's used.