Skip to main content

Access Grants

An access grant is your consent for another person or AI agent to access one of your resources — a data record, file, calendar, inbox, or similar — for a limited time. Grants expire automatically, can be revoked at any time, and every decision is logged for compliance.

How access grants work​

When a workflow, AI agent, or operator needs temporary access to your data, it creates a pending grant request and waits for your approval. You decide whether to allow or deny. If you approve, the grant becomes active and the requester can access the resource until the grant expires or you revoke it.

StatusMeaning
PendingRequest received — waiting for your decision
ActiveYou approved — access is live
DeniedYou declined — no access was given
ExpiredThe grant's time window passed — access ended automatically
RevokedYou ended the grant early before it expired

Receiving a grant request​

You may receive a grant request in several ways:

  • Chat message — the AI agent or a care coordinator asks for your consent directly in a conversation
  • DTMF prompt — during a phone call, you are asked to press a key to confirm
  • SMS confirmation — you receive a text and reply to approve
  • Workspace UI — a notification appears in your member profile under the Access Grants tab

Each request shows:

  • Who or what is requesting access
  • Which resource is being requested (e.g. "your care plan record")
  • How long the access would last (e.g. "for 60 minutes")

Approving or denying a request​

In a chat or phone call​

Respond as prompted — say yes or press the indicated key. The grant is recorded with your consent method automatically.

In the workspace UI​

  1. Open your profile (top-right menu → My Profile) and select the Access Grants tab, or navigate to your member page.
  2. Find the pending request in the list.
  3. Click Approve or Deny.
  4. The grant moves to Active or Denied immediately.

Denying a request does not affect your other data or access to the workspace — it only prevents this specific access.

Viewing your grants​

You can see all grants associated with you:

Grants received (others can access your resources)​

These are grants where you are the data owner who consented. Find them under:

  • Your member profile → Access Grants → Received

Each entry shows the requester, resource, consent method, status, and expiry time.

Grants given (you can access others' resources)​

These are grants where you are the party who was granted access. Find them under:

  • Your member profile → Access Grants → Given

Revoking an active grant​

If you change your mind after approving:

  1. Open your member profile → Access Grants → Received.
  2. Find the active grant you want to end.
  3. Click Revoke.
  4. Access ends immediately — the grant status changes to Revoked.

Revocation takes effect instantly. The requester loses access to your resource as soon as you revoke.

Expiry behavior​

Most grants include an expiry time set by the requester (for example, "access for the next 2 hours"). You will always be shown this duration before approving.

  • The system checks for expired grants every 5 minutes and marks them Expired automatically.
  • Expired grants cannot be reactivated — a new request must be made.
  • If no expiry time was set, the grant remains active until you revoke it or an admin ends it.

Standing tool consents (Approve Always)​

When the AI assistant asks for your approval to use a tool in a chat, a dialog appears with three choices: Deny, Approve (once), and Always. Clicking Always creates a standing tool consent — a special capability grant that lets the AI skip the approval dialog for that tool in future conversations.

What happens when you click Always​

  • A capability grant of type tool.always_allow is created and linked to your account.
  • For the remainder of the current conversation, and for all future conversations, the AI will use that tool without pausing to ask again.
  • The consent is specific to the tool and the context in which you approved it (for example, a grant made inside the manager workspace applies only to manager-context tool calls).

Viewing your standing consents​

To see all standing tool consents that have been recorded for you:

  1. Open your member profile → Access Grants → Received.
  2. Look for entries where the Resource type column shows capability. These are your standing tool consents.

The list shows each consented tool, when the consent was created, and when it expires (if applicable).

Expiry​

  • Manager-context tool consents expire automatically after 90 days. After expiry, the AI will prompt you for approval again the next time it needs to use that tool.
  • Tool consents granted in workflow and agent contexts do not have a default expiry — they remain active until you revoke them.

You can revoke a standing tool consent at any time:

  1. Open your member profile → Access Grants → Received.
  2. Find the capability grant you want to remove.
  3. Click Revoke.

Revocation takes effect on the very next tool call — any conversation that reaches a tool covered by that consent will stop and ask for your approval again immediately.

Compliance and audit trail​

All grant decisions — approvals, denials, revocations, and expiries — are recorded as consent events in the compliance audit log. This is required for HIPAA and SOC 2 compliance. You cannot delete grant history; records are retained per your workspace's data-retention policy.

If you have questions about a specific grant or notice unexpected access requests, contact your workspace administrator.