Roles & permissions

Control access for humans and AI agents through one model in Forest

Control access for humans and AI agents through one model in Forest

Control access for humans and AI agents through one model in Forest

Forest applies role-based and condition-based access to every read and every action. The same model scopes a human operator and an AI agent. Permissions live with the data, not in a separate identity tool.

Access control with fine-grained scopes that fits operational reality

Access control with fine-grained scopes that fits operational reality

Coarse-grained roles to start, fine-grained scopes where operations require them.

Preset roles

Admin, Developer, Editor, and User as starting points. Configure further from there.

Field-level permissions

Decide which fields a role can read, edit, or trigger actions on. Sensitive fields can be hidden from non-cleared roles.

Action-level permissions

Which actions a role can trigger, on which records, under what conditions. Permissions are part of the action's definition.

Conditional scopes

Permissions can depend on the record (segment, customer status), the actor (team membership), or the case state. Configurable without code.

Agents under the same model

An AI agent connects with a scoped role. It reads and acts only within that scope, with the same enforcement as a human.

External access for partners and BPOs

Partner teams or BPOs operate with scoped roles, restricted to the records and actions their scope allows. Audit captures their work the same way.

Built for layered ops

One permission model, your whole team and every AI agent under it

One permission model, your whole team and every AI agent under it

Field- and action-level scope

Decide what each role can read, edit, or trigger, down to the field and the action. Configuration, not code.

Same model for humans and AI agents

Your AI agents connect under scoped roles. They read and act only within their permission, like every operator.

Plugs into your IdP

Authentication stays with Okta, Auth0, Azure AD, or Google Workspace. Forest applies permissions after identity is settled.

Our support team and our trust and safety team each have access to the customer information they need to take the right actions.

Mark Rummel

VP Customer Experience

Our support team and our trust and safety team each have access to the customer information they need to take the right actions.

Mark Rummel

VP Customer Experience

Our support team and our trust and safety team each have access to the customer information they need to take the right actions.

Mark Rummel

VP Customer Experience

Frequently asked questions

You still have question ?
Book a conversation with a forest expert

How are roles defined in Forest?

Roles are defined in the Forest UI or via the SDK. Each role specifies field-level read, edit, and action permissions, plus conditional scopes (per segment, per customer state, per team).

Can we integrate with our SSO provider?

Yes. Forest supports SAML, OIDC, and SCIM. Common integrations include Okta, Auth0, Azure AD, and Google Workspace. Authentication is delegated to your IdP; Forest applies permissions after.

How are AI agents scoped?

Each agent connects with a credential tied to a role. The role defines what the agent can read and act on, exactly like a human user. The agent cannot exceed its scope.

Can we grant access to partners or BPOs?

Yes. External teams (BPOs, agencies, partner banks) can connect with scoped roles. Their access is limited to the records and actions they need; their work is audited the same way.

How are permissions audited?

Every action records the role and the conditions under which it was granted. Permission changes themselves are also recorded, so you can see who changed access and when.

Roles & permissions

LEVEL UP YOUR OPS GAME

One control plane. Every action traced - human, agent, BPO, LLM, workflow.

Roles & permissions

LEVEL UP YOUR OPS GAME

One control plane. Every action traced - human, agent, BPO, LLM, workflow.

Roles & permissions

LEVEL UP YOUR OPS GAME

One control plane. Every action traced - human, agent, BPO, LLM, workflow.

The ops orchestration layer for fintechs.

Copyright © 2026 Forest

Design by Alasta & Built by Reiya Studio