DocsWhat you can doWork with your team

For agents

Share with people. Limit what agents can do.

Invite colleagues to your organisation and give each agent its own key, limited to the catalogs it needs. You can take any of it back.

  • Agent-guided

Before you start: Claude Code (or any other agent)An admin login to your accountYour colleague's email

Say who needs what

Name the people and the agents, and what each one should be able to do.

Claude Code (or any other agent)Example conversation
You

Load our Q3 sales (~/Downloads/ventas-q3.csv) into LakehouseBox. Then give my colleague marta@example.com access to read it, and make a key for our reporting agent that can only read the sales, nothing else. Follow lakehousebox.com/docs/

Agent · example reply

Your CSV has 1,002 rows. First, approve this computer in your browser (tick write).

My plan:

  • Sales in their own catalog. Access is given per catalog, not per table, so keeping the sales apart is the only way to let the reporting agent read the sales and nothing else.
  • Reporting agent key: read access to sales only. Its key is shown once, so I'll save it to a file instead of printing it.
  • Marta: only an admin can invite someone, so I'll ask you to send that invite from your account page.
Example replies show what to expect. Your agent adapts to your setup.

Approve, then invite

Two steps only you can do: approve your agent's sign-in, and invite your colleague.

Your turn · in the browser

Approve your agent's access

Open the link your agent gives you, check the code, tick Write and approve.

Your turn · in the browser

Invite your colleague

On your account page, open Members, invite your colleague's email and choose member (or admin, if they should manage the account too). They get an email; the invitation is valid for 7 days, and if they have no account yet, signing up with that address applies it.

Your agent sets up and tests the key

It creates the key with exactly the access you asked for, and tests that it cannot do more.

Claude Code (or any other agent)Example conversation
You

done. The plan is fine.

Agent · example reply

Your Q3 sales are in LakehouseBox (1,002 rows, €355,529.32) and the reporting agent's key works.

I tested it: reading the sales works, it doesn't see your other catalog, and creating a table is refused. The key is saved in a file only you can read; I haven't shown it here.

Example replies show what to expect. Your agent adapts to your setup.
  • A separate catalog for the sales
  • A key for the reporting agent: read, sales only, tested
  • Your colleague invited as a member

Taking access back

Ask your agent; it tells you which steps need an admin.

Claude Code (or any other agent)Example conversation
You

I invited Marta. Anything else I should know?

Agent · example reply

To withdraw access later:

  • The agent: revoke its key, which also revokes any key it has made.
  • Marta: remove her from the organisation.
  • Copied connection settings: if someone copied a connection setup that contains the catalog's own credentials, revoking doesn't stop those. An admin must also rotate the catalog's credentials.
Example replies show what to expect. Your agent adapts to your setup.
Who can see what

People in your organisation are members or admins. Members can read every catalog by default; an admin can narrow a member to some catalogs, invite and remove people, publish catalogs and rotate credentials. Agents never use a person's login: each gets its own key, with read or write on the catalogs you choose, which you can revoke at any time from your account page. A key can create further keys with no more access than its own, and revoking it revokes them too.

  • Show me every key that can read the sales catalog.

  • Make Marta an admin.

  • Revoke the reporting agent's key.