Part of: Agentic AILast updated 3 September 2026 · 1 min read

What is scoped access (for agents)?

Scoped access means an AI agent is granted only the specific, named permissions it needs for a task, such as "read loyalty balance" or "initiate a refund," rather than broad or standing access to an account. Narrow, well-described scopes let a customer make an informed decision about what they are authorizing and limit the damage if an agent's credentials are ever misused.

Frequently asked questions

What happens if an agent's credentials are stolen?

Because access is scoped narrowly, an attacker can only perform the specific actions the agent was granted, not everything the customer's account can do.

Who decides what scopes an agent can request?

The business defines which scopes exist and are available to a given agent type; the customer decides which of those to actually approve.

Building the integration, not choosing it?Definitions stop where implementation starts. The developer docs carry the API references, SDKs and SCIM endpoints.
Developer doc

Ready to move beyond legacy CIAM?

Definitions are the easy part. Go live in weeks with identity that governs AI agents, customers, and partners from one place.

Learn more