Configure an agent's handlers and permissions
A handler is a person or company related to and responsible for an agent. Without a handler, the agent is limited to acting on its own data. Adding a handler establishes supervision but does not automatically grant every type of data access.
Add a handlerOpen the agent workspace, select Access & API key, and use Add handler. Search for the related company and select it. Confirm that the relationship represents the intended supervisor, not merely a client with a similar name.
Grant document accessEach handler row can include Grant access to read: Documents. Only that handler can change its own read grant. This prevents another company from unilaterally exposing the handler's documents to the agent.
Read-grant changes apply on the agent's next session. Current sessions retain the access context with which they started.
Remove accessRemove a handler when supervision ends, and revoke its read grant when document access is no longer needed. Start a new session to validate the new boundary. Also review assigned tools and stored credentials; those are separate access paths.
Least privilegeGrant only the data needed for the agent's defined task. Periodically review handlers, document grants, API-key use, tools, and session history.
Related articles: Create and manage a TimeSentry AI agent, Configure agent skills, tools, and credentials, Security and data privacy overview.