---
url: https://bishop.agentdeployment.co/running/access.md
description: Each interface's allow list, which decides who can reach the agent.
---

# Access

Each interface has its own `allow` list, and a message from anyone not on it never reaches the agent. **Leave an interface's list out and anyone who can reach the agent there can use it.** Set one before pointing anyone at the agent.

Every message is checked, not just the one that starts a thread, so someone who isn't allowed can't join a conversation another person started. Scheduled prompts are re-checked at every firing too, so removing someone stops what they scheduled.

## Slack

```json
{ "slack": { "allow": ["hayes.davis@example.com", "revops", "@sales-managers"] } }
```

`slack.allow` takes usernames, emails, and group names in one list, and Bishop works out which is which. A leading `@` is optional. Groups expand to their members, and Bishop refreshes the list every few minutes so a membership change lands without a restart. Someone not on it gets a reply only they can see. Bishop warns at startup when the list is missing.

An entry matching two different things, like a name that's both a person and a group, stops startup and says which candidates it found. An entry matching nothing logs a warning and Bishop keeps running, so a departed colleague's email doesn't take the agent down.

Another app is an entry like any other: list it by name and the agent will answer it, subject to the [limits on a bot-only exchange](/interfaces/slack#other-agents). Without a list, any app posting in a thread someone started can draw a turn, and what it posts is text nobody in the thread wrote. `slack.maxBotTurns: 0` keeps every app out.

## Email

```json
{ "gmail": { "allow": ["you@example.com", "@example.com"] } }
```

`gmail.allow` takes addresses and `@domain` entries, and an entry that is neither stops startup. A turn runs only when the sender **and** everyone else on the thread is allowed, because the reply goes to all of them. Someone not on it gets no reply at all. See [Email](/interfaces/email#mail-the-agent-never-answers).

## Microsoft Teams

```json
{ "teams": { "allow": ["hayes@example.com", "@example.com"] } }
```

`teams.allow` takes user principal names, `@domain` entries, or Entra object IDs. Without it, anyone in the tenant who can reach the app can use the agent. Somebody not on the list is told so.

## What an allowed person can do

An allowed person can direct the agent, which has a shell. Keep the list to people you'd trust with that shell, and consider the [sandbox](/running/sandbox) to keep the agent out of Bishop's own credentials and database.
