{"title":"Manage who can use an AI agent","slug":"manage-agent-access","url":"https://support.storeconnect.com/articles/manage-agent-access","url_markdown":"https://support.storeconnect.com/articles/manage-agent-access.md","subtitle":null,"summary":"Control which people can connect an AI agent to your stores from the StoreConnect Console. Turn agent access on or off for a user, set an expiry, reset a token that may have been exposed, and give each person the store role their agent needs.","type":"AI","video_url":"","keywords":"agent access, manage agent access, mcp access, api token, api token active, enable agent access, disable agent access, reset token, token expiry, storeconnect console, agents menu, store role, content changes role, revoke agent, offboarding, storeconnect administrator","last_modified":"2026-09-15T02:32:04+0000","body_markdown":"Use this process to decide who can connect an AI agent to your stores, and to switch that access off again. Agent access is per person: an agent signs in as one Salesforce user and can only do what that user's store role allows, on the stores that role covers. You manage it from the **Agent access** section of the StoreConnect Console.\n\nNothing here shows you anyone's token. Each person retrieves their own from **Connect an agent** in the Console, so a token is only ever seen by the person it belongs to. See [Connect an AI agent to your store](connect-an-ai-agent-to-your-store).\n\n## Who sees what in the Console\n\nThe **Agents** menu in the Console header shows different items to different people:\n\n- **Connect an agent** appears for everyone who can open the Console. It shows only that person's own access: their token, their stores, and their setup commands. It shows nothing about anyone else.\n- **Manage agent access** appears only for users who hold the **StoreConnect Administrator** custom permission, which the `storeConnect Administrator` permission set grants. Everyone else does not see the item, and the section behind it refuses to load without that permission.\n\nStore roles do not affect who sees the section. A `Content Changes` role decides what a person's agent may do; it grants no view of anyone else's access. The rest of this article is for the administrators who see **Manage agent access**.\n\n## How agent access works\n\nTwo things must both be true before a person can use an agent on a store:\n\n- They hold a **Store Role** of type `Content Changes` for that store. The role decides what the agent may do there. See [Store roles](store-roles).\n- **Agent access** is switched on for them. Switching it on generates a personal API token on their Salesforce **User** record (`API_Token__c`).\n\nThe token exists only while agent access is on and the Salesforce user is active. Switching access off, or deactivating the user, removes the token, and the agent stops working on its next request. An expiry date is optional and ends the access automatically.\n\nA role without agent access does nothing, and agent access without a role gives the person a token that reaches no store. The **Agent access** section shows you both halves side by side, so you can see which one a person is missing.\n\n## Before you start\n\n- You need the **StoreConnect Administrator** custom permission, as above. Without it the **Manage agent access** item is not shown to you.\n- To change another person's access you also need Salesforce's **Manage Internal Users** or **Manage Users** permission. Without it the Console still offers the actions, but Salesforce refuses the save and the message names the permission to ask for.\n- Your org needs the StoreConnect package at v21.12.0 or later, which is where the **Agent access** section and the token fields arrived.\n\n## Open the Agent access section\n\n1.  Open the **StoreConnect Console**.\n2.  In the header actions bar, open **Agents**, then select **Manage agent access**.\n\nThe **Agent access** section lists every person who holds a `Content Changes` store role or has agent access switched on. Search by name or email, or switch between the **All**, **Active** and **Inactive** tabs, each of which shows how many people it holds. Sort by **Name** or **State**.\n\nEach row shows the person's stores and a **State** chip:\n\n| State | Meaning |\n|---|---|\n| `Active` | Agent access is on and working. |\n| `Expires 2 Jan` | Access is on and will end at the end of that day. |\n| `Expired 2 Jan` | Access was on but the expiry has passed, so the token no longer works. |\n| `Inactive` | Agent access is off. The person may still hold a role. |\n| `User deactivated` | The Salesforce user has been deactivated, which removed the token. |\n\nA person with agent access on but no role is still listed, so live access can never disappear from view just because their last role was removed.\n\n## Turn on agent access for a person\n\n1.  Find the person in the list.\n2.  Open the row's actions menu and select **Enable agent access**.\n\nThe row confirms `Agent access enabled` and the person's token is generated. They retrieve it themselves from **Agents** \u003e **Connect an agent** in the Console. You do not see it, and do not need to.\n\nIf the person has no `Content Changes` store role yet, their token does nothing until you assign one. Select **Open store user roles** at the top of the section to assign it, following [Store roles](store-roles).\n\n## Change a person's role or scopes\n\nAn agent's sign-in session carries the permissions the person had when they signed in, and a session lasts about eight hours. Changing their **Store Role**, its **API Scopes**, or the stores it covers does not reach an agent that is already signed in. The change applies the next time a session starts. There are two ways to get there, and they are different.\n\n**The person signs in again.** This is the normal path. They sign in from their agent with the token they already have, and the new session picks up the new permissions. Nothing changes on their token and nothing is needed from you.\n\n**You disable and re-enable their access.** Use this when the change has to apply now and you cannot wait for the person to sign in. Select **Disable** on their row, then **Enable agent access**. Disabling ends every live session immediately. Enabling issues a new token, which means the old one no longer works: the person has to open **Connect an agent**, reveal the new token, and sign in with it. Tell them, because from their side the agent has simply stopped working.\n\n## Set an expiry (optional)\n\nSet an expiry when access should end on a known date, such as for a contractor or a fixed piece of work.\n\n1.  Open the row's actions menu and select **Set expiry…**, or **Change expiry (…)…** if one is already set.\n2.  Choose **In 30 days**, **In 90 days**, or **Pick a date**.\n\nAccess ends at 11:59 pm on that date in your own time zone, not the store's, and the expiry covers every store the person has a role on. The row's **State** shows `Expires` with the date. Select **Clear expiry** to remove it.\n\n## Reset a token\n\nReset a token when it may have been exposed, such as a token pasted into a chat or committed to source control.\n\n1.  Open the row's actions menu and select **Reset token…**.\n2.  Confirm.\n\nThe row confirms `Token reset`. The old token can no longer start a sign-in and a new one is generated. The person retrieves the new token from **Connect an agent** and signs in to their agent again. Neither value is shown to you.\n\nA reset does not end a session an agent has already started with the old token; that session runs until it expires, up to about eight hours. If the concern is that someone else may be using the token right now, select **Disable** first, which ends every live session immediately, then **Enable agent access** to issue the new token.\n\n## Turn off agent access\n\n1.  Open the row's actions menu and select **Disable**.\n\nThe row confirms `Agent access disabled` and moves to `Inactive`. The token is removed and the agent stops working on its next request. The person's store roles are unchanged, so enabling access again later generates a fresh token without any other setup.\n\n## When someone leaves\n\nDeactivating a Salesforce user removes their token automatically. The row shows `User deactivated` until it drops out of the list, so normal offboarding revokes agent access with no separate step.\n\nRemoving a person's last `Content Changes` role does not remove their token. Their row stays in the list with no stores, and their access stays on until you select **Disable**. Do both when someone should lose access entirely.\n\n## Work from the User record instead\n\nEverything above changes three fields on the Salesforce **User** record: **API Token Active**, **API Token Expires At** and **API Token**. If you would rather work there, clear **API Token Active** to disable access, set **API Token Expires At** for an expiry, or clear **API Token Active**, save, and select it again to reset the token. The fields are not on the standard User page layout, so an administrator has to add them first. For the field definitions, see [User object reference](user-object-reference).\n\nThe Console is the better place for day-to-day changes because it never displays a token value, whereas the **API Token** field on the record does.\n\nAfter enabling access and assigning a role, ask the person to open **Agents** \u003e **Connect an agent** and confirm the store they need appears under **Your stores**. That is the check that both halves are in place."}