Atlas

Atlas roles, privacy and key delivery

Use individual accounts and keep credentials out of conversations.

4 min read

Roles and bot permissions

Atlas is available to enrolled accounts with the required permissions. Account access does not enable every capability or grant access to another account's bots.

RoleAtlas access
OwnerAccount access, subject to enrollment and capability availability.
AdminUse Atlas must be allowed; account-level actions need their individual admin permissions. Owner-only actions remain with the owner.
Team memberAtlas assistant access on assigned bots; bot feature and action permissions still apply.

Team members cannot approve high-risk changes such as publishing, domain locks, creating keys, checkouts or connector removal. They cannot perform account-level actions such as billing, inviting staff or creating bots, owner-only actions, or deletes through Atlas.

An admin with billing permission can prepare checkout when that capability is available. Preparing checkout does not complete a payment. Owner-only actions remain restricted to the account owner, including for admins. Do not share an owner login to work around a denied action. Use the Team page and team roles guide to review assigned access.

Each consequential action needs its own review card and an explicit click on its approval button. Use Apply on hosted workflow reviews or Approve and its send, publish or delete variants on standard reviews. An ordinary chat yes is not approval, and a permission grant is not approval of a particular effect.

Share only what is needed

Use the minimum information needed for the task. Do not paste API keys, passwords or login tokens into Atlas, source documents or support messages. Review drafts and recipients before approving anything sent outside your account.

For retention and data-handling details, read the security and compliance guide and privacy policy. Do not infer a privacy or security guarantee from a task status.

Private key delivery

The key is delivered separately from the conversation. Keep the actual value out of screenshots, chat, documentation and support reports. Check the intended use and domain restrictions before installing it.

If delivery expires, fails or the response is lost, do not repeatedly request it or assume no key was created. Check the bot's Settings and existing keys first. Check the outcome before creating any replacement. If the delivery has expired, the app points to Settings to create a new key. Delivery expiry does not establish that no key exists. If the delivery was already issued, contact support to rotate the key. Any new creation in Atlas still needs its own review and explicit approval, where available. If you cannot establish the result, contact support without including the key.

Still stuck on something here?

Send us the article and the step you're on — we answer with specifics.

Contact support