Create Agent Account
Firm org admin provisions a new agent with granular permissions
π Firm Admin Portal
Agent's professional name
Must be under firm domain (policy enforced)
Granular control over agent capabilities
βοΈ Invitation Generated
Agent invitation link (expires in 7 days):
What Gets Created?
π€ Agent Account
New agent record with unique ID, linked to firm tenant. Email verified, awaiting passkey setup.
π Permission Profile
Granular permissions stored: which instruction types agent can issue, matter access level, approval rights.
π Invitation Token
Secure one-time token: AGENT-INV-E7F3-92A8. Time-limited (7 days), single-use, cryptographically signed.
π§ Onboarding Email
Sent to emma.thompson@shepwedd.com with setup instructions and passkey requirements.
Org Admin Control
Who Can Onboard Agents?
Only Firm Org Admins can create agent accounts. Platform root admins should not routinely create agentsβthey only create the firm and its first org admin.
- Create new agent accounts with specific permissions
- Assign agents to practice areas and departments
- Enable/disable high-risk permissions (e.g. bank instructions)
- Disable or revoke agent accounts immediately
- View all agent activity in audit logs
- Enforce device attestation and re-authentication policies
Permission Examples
β Standard Agent
Can send verified emails, verify client instructions, issue bank details, approve documents. Standard conveyancing solicitor.
β οΈ Restricted Agent
Can only verify client instructions (read-only). Paralegal or support staff who need to check authenticity but not issue instructions.
π High-Permission Agent
All permissions including managing client accounts and viewing all firm matters. Partner or senior fee earner.
π« Disabled Agent
Account deactivated. Portal login fails, device tokens invalid, Outlook add-in rejected. Used when agent leaves firm.
What Happens Next?
Agent Receives Invitation
Emma Thompson receives an email at emma.thompson@shepwedd.com with:
- Secure onboarding link with one-time token
- Explanation of passkey authentication requirements
- Instructions for device setup (must use work device)
- Overview of her role and permissions
- Link expires in 7 days for security