Skip to main content
Cedros

Controlling what the assistant can do

Set the assistant’s access by area, understand Read, Edit, and Publish, and review permissions and approvals before changes.

Use the assistant's tool settings to choose which parts of your site it can read or change. You can let it help with everyday content while keeping account settings, backups, and other sensitive areas restricted.

These settings apply to the site. You need permission to edit shared assistant settings to change them. If you are looking for help starting a conversation, see Getting started with the Cedros assistant.

Open the access controls

Go to Settings → Assistant → Tools. The What the assistant may do card summarizes the highest level of access currently granted anywhere on the site. Read the individual area rows to see where that access applies.

For example, the summary can show Publish because Site content allows publishing, while Team accounts remains Read. The summary does not mean every area has the same access.

If the page asks you to connect an intelligence provider first, follow Open Intelligence Settings. See Choosing AI providers and models for connection guidance.

Understand the four levels

  • None: the assistant cannot use tools in that area. This does not turn off chat or remove information already present in a conversation.
  • Read: the assistant can use that area's reading tools, but cannot use its tools to change records or settings.
  • Edit: the assistant can create and change items. It can prepare content drafts, but this level does not allow tools that require Publish access.
  • Publish: the assistant can also use that area's publishing and other actions that require this level.

Edit is not a promise that every change stays in a draft. Updating a record or a setting can take effect immediately. Use Read when you want the assistant to inspect an area without changing it.

Not every area offers all four levels. Everything it has means an area already has its highest available level; for example, an area with only reading tools cannot be raised to Edit.

Set access for the work you want

  1. Find the relevant row under Everyday work or Sensitive areas.
  2. Choose the lowest level that supports the task. For content you want to review before publishing, use Edit and explicitly request a draft.
  3. Review sensitive areas separately: Appearance and extensions, Site settings, Team accounts, Data and imports, and Backups and security. Leave them at Read or None unless you intend to allow changes there.
  4. Wait for the save status to confirm the change, then reopen the page and check the selected levels.

An area setting applies to the tools throughout that area. If you use Find a tool or area… to locate a particular action, changing the matching row still changes the whole area's access, not just the search result. Clear the search to review the full list afterward.

If no tools are enabled, Use the recommended setup offers a starting point: Edit for everyday work and Read for sensitive areas, limited to the levels each area supports. It does not grant Publish access. Review the resulting rows to make sure they fit your needs.

Use the whole-site control deliberately

The level control on What the assistant may do applies a level across every area, up to each area's available limit. Use an individual row when you only want to change one part of the site.

If some areas were held at lower levels, Cedros asks before replacing those differences. Read Set every area to…? before choosing Set them all, or cancel to keep the existing choices.

For example, setting the whole site to Publish can widen access well beyond the page you want published. To allow publishing only for content, change Site content and review the other rows separately.

Review suggestions to raise access

Tools or Overview may report that the assistant cannot finish work on a particular page and offer Raise… for one or more areas.

  1. Read which work is blocked and which areas the proposed change affects.
  2. Check the new level. A suggested fix grants that level across each named area, rather than allowing just one action.
  3. If it introduces Publish access or changes a sensitive area, review the confirmation details before accepting. If that access is broader than you want, cancel and keep the task within the current limits.
  4. After any change, wait for saving to finish and review the area rows again.

Some ordinary access increases apply without a separate confirmation. Read the proposed change before selecting the button.

If the message says your own account's permissions are blocking the work, tool settings alone cannot resolve it. Ask the site owner to review your account access. Granting the assistant a level does not override the permissions required by an action.

Keep requests and approvals specific

State the intended result in your request: “Show the answer here,” “Save a draft for review,” or “Publish this reviewed page.” Include the exact item and the changes you want. Writing useful requests for the assistant has examples you can adapt.

Request wording guides the work; it does not change the configured access levels. A request to publish cannot supply a missing permission, and asking for a draft does not lower the site's tool settings.

When an approval card appears, read the action, target, and any details or cautions before deciding. Reject an action that does not match your request and explain the correction. Wait for the decision status to update; Sending decision is not yet an accepted approval.

An approval allows the described action to proceed. It does not establish that the action completed successfully. Review the assistant's result and open the affected item to confirm what happened. If the card expires or says the decision did not send, check the conversation and connection before trying again.

Reduce access when it is no longer needed

Choose Read to keep lookup access while removing editing and publishing from an area, or None to remove its tool access. To remove tool access across the site, select None in the top card and review any confirmation.

Wait for the change to save. Lowering access does not undo completed work. If the assistant is already working on something you want to stop, use the chat stop control, review queued requests, and check any affected records as well.

For content that has already been saved or published, follow Understanding drafts, previews, and publishing to review its current state.

Resolve common problems

  • The controls are read-only: ask an administrator for permission to edit assistant settings.
  • The top level looks higher than one area: it summarizes the highest access on the site. Check the area's own selection and the listed exceptions.
  • An action is still unavailable: review both its area's tool access and your account permissions. Also check any provider setup message; broader tool access will not repair a missing provider connection.
  • A change did not save: read the save error. If settings changed elsewhere, reload the current values and reapply only the changes you still want.
  • A request failed after it may have changed something: open the affected item before repeating the request, especially if it may have published, sent, or deleted something.