How Levi's permissions work
Levi, your AI teammate · nineloops support
Levi runs as you, and on top of that every capability is allow, ask first or never, with money and record ceilings.
Two separate things decide what Levi may do. Your own permissions decide what it can reach at all. The workspace rulebook decides what it may do without stopping to ask.
It runs as you
Every action Levi takes carries your sign-in. Row level security in the database answers each read and each write exactly as it would if you had done it by hand, so Levi cannot open a record you cannot open, cannot act beyond your role, and cannot reach another workspace. There is no separate AI account with wider access.
Allow, ask first, never
On top of that, every capability has a mode. Allow means Levi runs it. Ask first means Levi does not run it: it parks the exact request and waits for a person. Never means it is refused, and the refusal is recorded like anything else.
The rules live in the database and are resolved on every single request, so they hold whatever the model believes it should do. A capability nobody has written a rule for uses the built-in default, and anything the rulebook has never heard of defaults to asking rather than to running, so a capability added later cannot quietly inherit permission.
What the defaults are
- Reading, searching, forecasting: allowed. Nothing changes, and your own permissions still decide what is visible.
- Creating and updating records, writing a document, creating a design, drafting a WhatsApp campaign: allowed, because your permissions already gate them, every one is recorded, and every one can be undone.
- Email, WhatsApp messages, launching a campaign, chat messages to a teammate: ask first. These reach a person and cannot be taken back.
- Raising or sending an invoice: ask first.
- Creating or changing an automation: ask first, because it keeps acting long after the conversation ends.
- Building or removing a tab, or adding a field to one: ask first, because it changes what everyone else sees.
Money and record ceilings
Any capability can also carry a money ceiling and a record ceiling. These do not block on their own, they escalate: an action above the ceiling becomes an approval request even when the mode is allow. A ceiling breach always has to be decided by an admin, rather than waved through by whoever asked for it.
Where to set them
- Open Settings, then Levi permissions.
- Choose who the rule is for: everyone, or one role. A rule written for a role beats the rule written for everyone, and anything you leave alone follows the wider rule.
- Set each capability to Allow, Ask first or Never.
- Open Ceilings on a capability to add a money limit or a record limit, then save. Remove a rule and that capability goes back to following the wider rule, or to the built-in default.
Only owners and admins can change these rules. Every member can read them, because people are entitled to know when Levi will stop and ask. The rules engine also resolves a rule written for one individual, which beats their role; the Settings editor writes the everyone and role rules today.
More in Levi, your AI teammate
- What Levi can do in your workspace
- Approving what Levi wants to do
- Seeing and undoing what Levi did
- Building new tabs with Levi
- When Levi needs a platform build
Still stuck?
Raise a ticket and a person who works on nineloops will pick it up.
<a href="/support">All support articles</a>