← Help centre

Agent access

Signed in? Ask Lovelio this question inside the app - it answers from this same page.

Settings > Integrations > Agent access is the whole of your agency's agent posture on one page: who may connect an AI agent, what that agent is allowed to read and do, and what has left the business. Admins only. Pausing a person sits on Settings > Workspace > Users. There is nothing to set up: the rules below are already on.

What counts

On screen never counts. Reading profiles and CVs in Lovelio is the job, and nobody monitors it.

Leaving Lovelio always counts. A candidate is "taken out" when a copy exists outside Lovelio:

  • a CV or document file downloaded in the app;
  • a row exported to CSV from the candidates list;
  • any candidate returned to an agent or API key, because that record now sits on a machine outside Lovelio. For an agent, a read is a download.

Each candidate counts once per person per day, whichever door it left through and however many times. Fifty downloads of the same CV in one day is one candidate. A profile and its CV are one count; the "Of which CV files" column says how many of them included a file.

The daily stop for agents

An agent or API key acting for a consultant (anyone who is not an admin) can take out 200 candidates a day, unless you change the number on this page, then it is refused with: "You have reached today's limit for candidates taken out. Ask an admin if you need more." Candidates it already took out today do not count again, so re-reading the same records is free. The allowance resets with the person's own day. Keys held by an admin have no stop. You can set a different number for the whole agency or for one person, and you can choose "carries on and tells an admin" instead of stopping, which counts and alerts but never refuses a call.

Who can connect an agent

A consultant can connect their own AI agent from the agent's own app. They sign in to Lovelio, see exactly what the agent will get and what your rule refuses, and ask to connect. An admin approves it here before it reads anything.

Two sentences at the top of the page decide this:

  • Consultants can connect agents, or cannot. Turn it off and only admins can connect anything.
  • A new connection needs an admin to approve it, or goes live straight away.

You always get an email and a notification when someone asks. They get an email when it goes live.

What an agent is allowed to do

Three levels, in plain words. "Default level" applies to every consultant unless you set one person differently; team leaders get the same plus their team's desks.

  • Look only: reads candidates, CVs, jobs, clients, pipeline, submissions and interviews. Changes nothing.
  • Recruiter (the default): everything in Look only, plus adds notes, moves stages and updates candidate records. Cannot submit, book or email.
  • Full desk: everything in Recruiter, plus sends submissions, books interviews, creates jobs and sends email as the consultant. Also reads placements without fees, talent pools, forms, quotas and analytics.

"Adjust settings" opens a table of records with No access, Read or Read and write per row. Changing a row makes the level fine-tuned; picking a level again resets it. Candidates and their CVs are always readable. Fees and money, recruiter DNA, integrations, marketplace, webhooks and account details sit under "more" and are off in every level. Agents never touch users, settings, API keys, billing or deleting records.

The agent uses the connected person's current role and record access. Granting a scope does not make a consultant an admin. Manage role permissions in Settings > Workspace > Permissions. Direct account administration requires an admin; capabilities locked in the Permissions screen retain their role limits. Personal OAuth and app-install credentials cannot create replacement API keys; create these yourself in Settings > API.

Adding permissions requires the person to reconnect and consent again. An existing token never gains extra access from a rule or key change. Removing permissions narrows subsequent calls.

Each person in the People table has their own level pick: Default, Look only, Recruiter, Full desk or Off. Default follows the company level when it changes; any other pick pins them. Click a name to fine-tune one person or change their daily limit; that leaves the default alone for everyone else.

Waiting and connected

A request waiting for you shows as a banner at the top and inside the person's panel, saying which level the agent will get and anything extra it asked for. Three choices:

  • Approve: the agent gets the person's level and the rest is dropped. This is the one to use.
  • Approve with (the extras): shown only when the agent asked for more than the level allows; grants the extras too.
  • Decline: nothing is connected.

"Connected now" lists their live agents, when each was connected, when it was last used, and a Revoke button. Revoking takes effect on the next request, not in five minutes.

Pausing someone

Pausing lives on Settings > Workspace > Users: the pause icon on the person's row. This page shows a red "Paused" tag when somebody is paused, and the person's panel links across.

Pausing signs them out everywhere, stops them signing back in, and revokes every API key and agent connection acting for them. Nothing they own is deleted or reassigned: their candidates, jobs, notes and their name on the timeline stay exactly as they are. Restoring lets them sign in again; their keys stay revoked and they reconnect their agent, which is the safe way round.

Removing someone from the workspace does the same revocation automatically.

When someone is far above their usual

Every admin gets one email and one notification a day when a person's week or month goes past three times their usual. It is a nudge, not an accusation, and the same threshold colours the cells on this page. One alert per person per day, whatever else happens.

The page

  • People: each person, their agents (waiting or live), their level pick, and how many candidates they took out today. Company API keys with no person behind them show as "API key".
  • Candidates accessed: the same number per person by week or by month, every period since the person first took something out, with their usual number and an all-time total. A cell turns amber when the period is three times the person's usual and red at ten times. Usual is the average of their completed weeks (or months) so far. Small numbers never colour: a week under 15 candidates or a month under 60 is never amber.
  • Click a person for the full history split by door: pulled by agent, downloaded in app, exported to CSV. "Download history as CSV" gives the owner a file for their records.

History is never pruned. The suspicion is often found weeks later, so the page looks back as far as the data goes.

CSV export

Export CSV on the candidates list is for admins and team leaders only, and every exported row counts as a candidate taken out.

What it cannot see

A person paging the candidates table with their browser's developer tools gets profile text without CV files, and nothing counts it. Screens can be photographed. The page makes bulk copying slow, visible and attributable; the access history is what turns a suspicion into evidence.