How to Control Which AI Tools Each Team Can Use

Last updated ·Reviewed by Karim Rahme·Read as Markdown
Answer

Control AI tool access by team with groups, not individual grants. Create a group per team, ideally matched to your identity provider groups, and allow or deny each integration and skill for each group. Within each integration, expose only the tools that team needs, and keep write tools off until you have seen how people use the read ones. In Metorial, every integration and skill has the same Allow and Deny controls per group.

Giving every team every tool is the fastest way to fail a security review and the fastest way to confuse a model. Access by team fixes both, as long as it is managed by group rather than one person at a time.

If you need to
Use
Give a whole team the same tools
A group, allowed on each integration
Keep a team away from one system
A Deny rule for that group
Give one person a temporary exception
A direct grant on their account
Allow reads but not writes
Expose only read tools in the integration

How do you set up access by team?

1. Create a group per team. In Metorial, open Workforce, then Access, then Groups, and create one for each team. Turn on default assignment only for a group every new account should join.

2. Match it to your identity provider. Access groups can match SSO group IDs, so group membership follows the directory rather than a list someone maintains.

3. Choose the tools in each integration. When you create an integration, select which of its tools it exposes. A support team's Salesforce integration might only read cases and accounts.

4. Allow or deny each resource per group. Open an integration or skill, add a group in its Access section, set it to Allow or Deny, and save. Integrations and skills use the same controls.

5. Check it as a user. Preview the portal as someone on the team and confirm they see only what they should.

How do you handle exceptions?

Grant access directly on a person's account only when one person needs something their team does not. Review direct grants on a schedule and remove them when they end. If three people need the same exception, it is a group.

How do you review access?

Open an account's Access view to see its groups and any direct grants. Open an integration to see which groups can use it. Because every call is logged in Tracing, you can also check whether a group actually uses what it has, and remove what it does not.

Why does limiting tools help the model too?

A model shown hundreds of tools reads every description on every request and picks worse. A team that sees fifteen relevant tools gets faster, more accurate answers. See Access control for how policies follow the person behind each agent.

Frequently asked questions

Why use groups instead of per-person access?

Per-person grants drift. After a few months nobody can say why someone has access to something. Groups keep access consistent and make a review a matter of reading a short list.

Can a group match our identity provider groups?

Yes. In Metorial, portal access groups can apply to every account by default or match SSO group IDs, so joining a team in the identity provider grants the right AI tools.

What if one person needs access their team does not have?

Grant it directly to that person as an exception, and remove it when it is no longer needed. If several people need the same exception, make it a group.

Can we limit tools within an integration?

Yes. Each Metorial integration exposes a chosen set of tools, so a team can get read tools for a CRM without the tools that delete records.

Does access control also apply to shared skills?

Yes. Skills use the same Allow and Deny controls as integrations, and a skill can only use integrations the person running it has access to.

Sources

  1. Metorial documentation: Grant Workforce access
  2. Metorial documentation: Create an integration
  3. Metorial documentation: Manage Workforce accounts

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.