How Levi's permissions work

Levi, your AI teammate · nineloops support

Levi runs as you, and on top of that every capability is allow, ask first or never, with money and record ceilings.

Two separate things decide what Levi may do. Your own permissions decide what it can reach at all. The workspace rulebook decides what it may do without stopping to ask.

It runs as you

Every action Levi takes carries your sign-in. Row level security in the database answers each read and each write exactly as it would if you had done it by hand, so Levi cannot open a record you cannot open, cannot act beyond your role, and cannot reach another workspace. There is no separate AI account with wider access.

Allow, ask first, never

On top of that, every capability has a mode. Allow means Levi runs it. Ask first means Levi does not run it: it parks the exact request and waits for a person. Never means it is refused, and the refusal is recorded like anything else.

The rules live in the database and are resolved on every single request, so they hold whatever the model believes it should do. A capability nobody has written a rule for uses the built-in default, and anything the rulebook has never heard of defaults to asking rather than to running, so a capability added later cannot quietly inherit permission.

What the defaults are

Money and record ceilings

Any capability can also carry a money ceiling and a record ceiling. These do not block on their own, they escalate: an action above the ceiling becomes an approval request even when the mode is allow. A ceiling breach always has to be decided by an admin, rather than waved through by whoever asked for it.

Where to set them

  1. Open Settings, then Levi permissions.
  2. Choose who the rule is for: everyone, or one role. A rule written for a role beats the rule written for everyone, and anything you leave alone follows the wider rule.
  3. Set each capability to Allow, Ask first or Never.
  4. Open Ceilings on a capability to add a money limit or a record limit, then save. Remove a rule and that capability goes back to following the wider rule, or to the built-in default.

Only owners and admins can change these rules. Every member can read them, because people are entitled to know when Levi will stop and ask. The rules engine also resolves a rule written for one individual, which beats their role; the Settings editor writes the everyone and role rules today.

More in Levi, your AI teammate

Still stuck?

Raise a ticket and a person who works on nineloops will pick it up.

<a href="/support">All support articles</a>