Agents and permissions
Give each agent a purpose and deliberate access.
A named definition
An agent is a definition resolved by the shared runtime. Its definition includes a name, instructions and a voice. Installation-specific definitions and credentials are kept on your server.
Deliberate access
Choose the tools and connections each agent may use. Configure access for its work rather than assuming every agent should see every account. Permission changes must be applied through the installation's supported controls.
Model access
Model providers require API access. A consumer chat subscription does not supply API credentials. Model usage may incur provider charges, independent of where you host Lares.
Check readiness
An agent being listed does not mean it is ready to work. Check runtime health and complete a real conversation before relying on it.