Agent Security

Rock's agents work within the same security model you already use everywhere else in Rock. The roles, permissions and access controls you've set up apply here too.

Note

New agents start locked down.
When you create a new agent, Rock restricts access to RSR - Rock Administrator by default. That is intentional - agents can write data, so Rock errs on the side of caution. Before staff can use a new agent, open the agent security and grant View access to the right role. For most organizations, RSR - Staff Workers is the right starting point for internal use.    

Security works in layers

Agent security has three layers.

  1. The agent itself. Click the ti ti-lock lock to select which security roles have access to view or edit the agent.
  2. Skills. Each skill can be secured independently. If someone doesn't have permission to use a skill, the agent won't run it for them, even if the skill is assigned to the agent.
  3. Tools. Individual tools carry their own permissions too.
  4. Entities. When an entity has security settings, any tool that works with that entity respects them. If a person can't view contribution records in Rock, the agent can't show those records to them either.

The agent isn't a shortcut around your permissions. It works within them.

Here's an example of how to secure an agent...

Secure an Agent

Then an example of how to secure a skill or tool...

Secure a Skill or Tool

  1. Skill Security - Secure the entire skill here. Only people with permission can use its tools through the agent.
  2. Tool Security - Secure a single tool here. Use this to allow the skill but restrict specific actions within it.

Internal vs. Public

The Audience setting on each agent (covered in Configure an Agent) also shapes what data the agent can share. A public agent should carry only the skills appropriate for an unknown visitor. Think carefully about which skills you attach and keep the set narrow.

What Spark sees

Spark Development Network does not have access to your organization's data. Your configurations, instructions and conversation history stay within Rock and the AI provider you've configured.