Edit one page without publishing it
Grant page reading and editing for one profile. Keep publication, address changes and deletion outside the role.
Control capabilities, specific resources, connected API tools, budgets and access periods. Review requests, change the policy and revoke access from one workspace.
The workspace policy is a ceiling. Effective access combines the granted scope, current policy, selected resources, credential validity and agent connection.
Grant page reading and editing for one profile. Keep publication, address changes and deletion outside the role.
Use a dedicated channel credential and approved read operations. Public messages cannot expand fixed API arguments.
Connect the account through a reviewed integration, authorize an exact tool for one agent and remove it without exposing the provider credential.
An owner can grant selected administrative areas to a root agent. That authority is explicit, expires and is not inherited by child credentials.
The policy becomes useful when it changes what an agent can see and do at the moment of the call.
Select the page, allow reading and editing and keep address changes and deletion outside the role.
Explore →02 · SupportUse a channel credential and a dedicated agent environment for visitor driven input.
Explore →03 · OperationsAuthorize the exact operation for one agent without showing it the provider credential.
Explore →Documents and prompts explain intent. instanceof.ai checks the credential, scope, policy and selected resource before executing its tools.
No. It may explain and request missing scopes. A person reviews the request, and approval cannot exceed the workspace policy.
It controls instanceof.ai tools and external API operations connected through its integration layer. It does not control unrelated browser sessions, files or credentials already available on the agent host.
New calls recheck the live credential and policy. Revocation cannot undo an external action that already completed.
Connected credentials remain with the provider or in the credential vault. The agent receives the approved operation, not the secret.