Agents

How to scope file access for an agent using Suite

Turn an agent’s assignment into focused file access and a clear output path using Suite’s supported permissions.

Give the agent the files it needs to do useful work

Suite’s administrator-managed file and folder access can support a focused assignment for an authorized agent on a supported host. Define the inputs it needs, the outputs it may create and any existing files it may modify. Map that scope to the available permissions and verify it as the identity doing the work, so the agent can contribute with a clear, reviewable brief.

Use Suite’s documented permissions and setup flow, with the administrator approving the agent’s access brief.

Make a small access brief

Consider a proposed task that reads approved source clips and writes analysis reports. Its brief could contain:

  • Input area: the approved clips needed by this job, including any required sidecar files.

  • Output area: a designated location for new reports, with a naming convention that avoids existing deliverables.

  • Allowed changes: whether the task may only create new outputs or also replace specific existing outputs.

  • Excluded actions: unrelated browsing, deleting source clips, renaming shared folders or creating external transfer links unless separately required.

  • Operating identity: the Suite user and host process that will run the job.

  • End condition: who reviews the outputs and when temporary access should be reconsidered.

These are requested boundaries. Confirm which controls enforce them in the actual environment; writing a restriction in a prompt does not establish a filesystem permission.

Check what Suite permissions actually cover

Suite's User Permissions guide describes file and folder access for team members, with separate controls for creating external transfer links. It also says administrators have access to the entire drive by default. An administrative identity is therefore a poor default for a narrowly scoped file-processing evaluation.

The same guide explains that access to a selected folder includes its contents and subfolders, and that renaming a file or folder changes its path and requires permissions to be added again. Choose a stable test area and recheck access after a path change. Do not assume a folder restriction stays correct as the workflow changes.

Confirm the required read and write behavior with the administrator rather than inferring a detailed permission model from a short overview. In particular, this guide does not establish a special write-only output mode or promise that every requested action can be restricted independently.

Include the host process in the check

An agent application may run under a different host identity from the person who installed Suite. Check the intended process, path and access together. On Linux, the CLI configuration reference documents a setting that allows other local users to access the drive; its default limits access to the user who started the service. Treat widening that access as an administrator decision, not a routine workaround for a failing job.

For customer-owned storage, have the owner confirm the supported connection policy as well. Suite user permissions and the storage-provider connection are different parts of the setup. Do not invent a bucket policy or infer it from the agent's task description.

Verify the boundary with harmless samples

Before processing real material, ask the administrator to prepare an allowed sample and an out-of-scope sample for a controlled access check. Confirm the expected result for each. Do not use unrelated private files as test targets or modify original material merely to prove a restriction.

Record the identity, approved scope, observed result and unresolved controls. Review the scope when inputs, output destinations or responsibilities change. When the task ends, return the access brief and results to the owner so temporary access can be reviewed through the normal supported process.

Put the idea to work

Start with your workflow.

Bring shared files into your familiar applications with Suite Managed, or connect your own supported storage with S3 Native. S3 Native requires at least 20 TB of active storage.