AgentBox Docs

Groups & Access

Understand the many-to-many access relationship between sub-accounts, groups, and agents.

The three objects

AgentBox access control is built from three objects:

  • Sub-accounts: managed accounts created by admins for students, employees, customers, or other end users.
  • Groups: collections of sub-accounts, such as classes, departments, project teams, or customer groups.
  • Agents: AI capabilities configured and enabled by admins, then granted to groups.

Sub-accounts are separate from the admin account system. Admins and members use primary accounts for the dashboard, while sub-accounts sign in through the workspace portal and use authorized agents.

Many-to-many access

Groups connect sub-accounts and agents:

  • A sub-account can belong to multiple groups.
  • A group can contain multiple sub-accounts.
  • An agent can be granted to multiple groups.
  • A group can have multiple agents.

This lets you distribute the same agent to multiple classes, or let one class use several agents.

Which agents a sub-account can access

A sub-account can access the union of all agents granted to the groups it belongs to.

For example:

  • A sub-account belongs to Class A and Writing Lab.
  • Class A has access to English Tutor.
  • Writing Lab has access to Essay Reviewer and Grammar Coach.

After signing in, that sub-account can see English Tutor, Essay Reviewer, and Grammar Coach. If the same agent is granted through multiple groups, it appears only once in the available agent list.

Current management entry points

Common entry points include:

  • Sub-accounts page: create sub-accounts, batch import sub-accounts, and assign groups.
  • Groups page: create groups and review sub-account and agent counts.
  • Group detail page: add or remove sub-accounts and agents from a group.
  • Agent Settings tab: choose which groups can access the current agent.

The sub-account portal only returns agents that are both enabled and authorized for the current sub-account. Disabled agents do not appear in the available list.

Create groups that match your real organization first, then create or import sub-accounts and assign their initial groups. After an agent is ready, grant it to the target groups and sign in with a test sub-account to verify the visible scope.