Skip to navigation

Keys and access levels

What a key is, and how an access level decides what it can do.
View as Markdown

Keys

Every agent and every program connects with a key. A key starts with bsmt_ and belongs to one organization. Basement shows a key one time, when you create it, and keeps only a hash of it.

A key says what is on the other end:

KindConnects withShown as
AI agentMCPThe agent’s own character
ProgramThe SDKs or the HTTP APIA terminal

The kind does not change what the key can do. It names what is using the key, so the list of connected keys and the activity log can tell a system from an agent.

To stop a key, revoke it in Agents, Connected. It stops working immediately, and its past calls stay in the activity log. To change a key, revoke it and connect again with a new one.

Access levels

An access level decides what a key can do. It has four parts:

PartWhat it controls
Basement dataWhether the key reads documents, files and skills, and whether it reads tasks.
Write accessWhether the key can create and change documents, files, skills and tasks. Without it, the key only reads.
Connected servicesFor each service (for example Jira), no access, read, or read and write. Or the same level for all services.
FoldersWhich folders of files and skills the key can use. By default, the folders the person who connected it can use.

Basement comes with two access levels:

  • Researcher reads everything in Basement and writes nothing. It uses no connected service.
  • Operator reads everything that Researcher reads, and writes documents, skills, files and tasks. It uses no connected service.

Admins and owners create other access levels in Agents, Access levels, for example one that reads documents and can open tickets in one service.

A key without an access level reads everything in Basement, writes nothing and uses no connected service.

A key never has more access than the person who connected it. An agent reaches the folders and the connected accounts that its person can reach, and no others.

Who can do what

Role in the organizationAgents and programs
Owner, AdminConnect and revoke any key, create access levels, see everyone’s activity, download older activity.
Editor, ViewerConnect their own agents and programs, and see the activity of those.

When a person leaves the organization, Basement revokes the keys that person created there.

Limits

A key can make 240 calls per minute. Above that, the Gateway answers 429 until the minute ends. See Errors and limits.