There is one permission model, and you already know it
The agent is a CMS user. Not a special kind of integration with its own settings screen and its own idea of what it may do — a row in the same table as your staff, in a group you chose.
That has consequences worth spelling out:
- You widen or narrow what the agent can do by editing a group, not by reissuing a token or asking us to change anything.
- A tool you buy later is reachable by the agent the day its group gets it.
- The list of tools the agent is handed is your permission model, written out.
There is no second set of rules to keep in step with the first, which is the whole design. And it is bounded twice: what your installation includes, then what the group grants.