An access policy decides how much the people in a role may use the AI Assistant, and with what. You manage them under Settings → Artificial Intelligence → Security Models, in Access policies. You need Manage AI Settings.
This is not the same thing as the security models under My Account → Branch Types, which govern sub-organizations. These only govern AI use.
What a policy holds
- Policy Name and Description.
- Limits:
- Max Tokens / Day and Max Requests / Day: how much each person in the role may ask of the AI in a day. Empty means no limit.
- Max Context Length: the most text one request may carry.
- Allowed Providers and Allowed Models: which of your connected providers and models the role may use. Leave them empty to allow everything that is switched on.
- Allow Image Upload: whether people may give the AI images to read.
- Allow MCP Tools: whether people may use tools from your MCP servers in the AI Assistant. See MCP Servers Explained.
- Role Assignments: the security roles the policy applies to.
A person's limits come from the policies assigned to their roles, the same way their other permissions come from their roles. Someone with several roles must stay within every policy that applies to them.
Create one
- In Access policies, click Add policy.
- Name it, set its limits and choices, and pick the roles it applies to under Role Assignments.
- Click Create policy.
To change one later, edit it in the list and click Save policy. If a provider, model or role it named has since been removed, Kamo asks you to reload the page and choose again.
General AI Settings
The bottom of the same tab holds settings for the whole organization:
- Default System Prompt: the instructions every AI Assistant conversation starts with, unless something more specific overrides them.
- Auto-select best available model: let Kamo choose the model when a person has not picked one.
- Required text for every agent: Required opening text and Required closing text are added to the instructions of every persona and AI team member in your organization, for anything your business is required to say, such as a disclosure. Their authors can see this text but cannot change or remove it, and saving it applies it everywhere straight away.
AI team members
An access policy applies to everyone who holds the role, AI team members included. An AI team member is limited in two more ways: what it may spend is capped by its budget, and what it may do is set by its charter. See Routing & Budgets Explained and The AI Charter Explained.
Related articles
Other guides that answer questions close to this one.
How to Configure General AI Settings
Set your organization's default instructions for the AI Assistant, whether Kamo picks the model, and the text every AI agent in your organization must include. Before you start You need the Manage AI Settings…
How to Create an AI Access Policy
Set how much the people in one or more roles may use AI each day, and which providers and models they may use. Before you start You need the Manage AI Settings permission. See AI Security Models Explained for what a…
AI Providers Explained
An AI provider is your organization's account with an AI service: where it is, and the key that pays for it. The AI Provider Registry (Settings → Artificial Intelligence → AI Provider Registry) keeps every provider you…
How to Create an AI Sales Agent
Create an AI sales agent, which the screens call a persona: a named character that answers chats on your website, trained on your industry and your offer. A persona is a job title whose charter is its instructions, so…
Routing & Budgets Explained
Two questions every AI request answers: which model does the work, and may this AI member spend any more today? Settings → Artificial Intelligence → Routing & Budgets is where you answer both for your organization. You…
What You Can Do with the AI Assistant
AI Assistant (nav icon, top navigation bar) is a chat window you can open at any time to ask questions and get answers, without leaving whatever else you're doing in KamoUniverse. It opens as a floating window (like…
