DocsWhat you can doWork with your team
For agentsShare with people. Limit what agents can do.
Invite colleagues to your organisation and give each agent its own key, limited to the catalogs it needs. You can take any of it back.
Before you start: Claude Code (or any other agent)An admin login to your accountYour colleague's email
Say who needs what
Name the people and the agents, and what each one should be able to do.
Load our Q3 sales (~/Downloads/ventas-q3.csv) into LakehouseBox. Then give my colleague marta@example.com access to read it, and make a key for our reporting agent that can only read the sales, nothing else. Follow lakehousebox.com/docs/
Your CSV has 1,002 rows. First, approve this computer in your browser (tick write).
My plan:
- Sales in their own catalog. Access is given per catalog, not per table, so keeping the sales apart is the only way to let the reporting agent read the sales and nothing else.
- Reporting agent key: read access to sales only. Its key is shown once, so I'll save it to a file instead of printing it.
- Marta: only an admin can invite someone, so I'll ask you to send that invite from your account page.
Approve, then invite
Two steps only you can do: approve your agent's sign-in, and invite your colleague.
Your turn · in the browser
Approve your agent's access
Open the link your agent gives you, check the code, tick Write and approve.
Your turn · in the browser
Invite your colleague
On your account page, open Members, invite your colleague's email and choose member (or admin, if they should manage the account too). They get an email; the invitation is valid for 7 days, and if they have no account yet, signing up with that address applies it.
Your agent sets up and tests the key
It creates the key with exactly the access you asked for, and tests that it cannot do more.
done. The plan is fine.
Your Q3 sales are in LakehouseBox (1,002 rows, €355,529.32) and the reporting agent's key works.
I tested it: reading the sales works, it doesn't see your other catalog, and creating a table is refused. The key is saved in a file only you can read; I haven't shown it here.
- A separate catalog for the sales
- A key for the reporting agent: read, sales only, tested
- Your colleague invited as a member
Taking access back
Ask your agent; it tells you which steps need an admin.
I invited Marta. Anything else I should know?
To withdraw access later:
- The agent: revoke its key, which also revokes any key it has made.
- Marta: remove her from the organisation.
- Copied connection settings: if someone copied a connection setup that contains the catalog's own credentials, revoking doesn't stop those. An admin must also rotate the catalog's credentials.
Who can see what
People in your organisation are members or admins. Members can read every catalog by default; an admin can narrow a member to some catalogs, invite and remove people, publish catalogs and rotate credentials. Agents never use a person's login: each gets its own key, with read or write on the catalogs you choose, which you can revoke at any time from your account page. A key can create further keys with no more access than its own, and revoking it revokes them too.
Show me every key that can read the sales catalog.
Make Marta an admin.
Revoke the reporting agent's key.