docsuse castaccess

Access

Cast doesn't let strangers in. The first message from anyone you haven't allowed is held, and you approve it from the dashboard, once or for good.

How access works

Same flow on every transport. It begins the first time someone messages the agent.

  1. Someone messages the agent. The server resolves who they are. If you haven't granted them, the message is held. It doesn't reach the agent yet.
  2. The held message surfaces as a pending approval in the dashboard, on the agent's row. You see who's asking and what they sent.
  3. You allow or deny it in place. Allow once lets this single message through. Allow always grants durable access, and the held message replays into the agent right away.
  4. After an always-grant, their messages reach the agent directly. No second step.

Only the people you act on get through. A stranger you never approve stays held, and the agent never sees them.

Approving yourself

When the person is you, there's no waiting. Open the agent's chat URL (or message it on whatever transport you set up), then switch to the dashboard and allow yourself always. You're in. Same approval, no out-of-band step, because both ends are your own.

Blocking and revoking

Three states, not two. Someone is granted (their messages reach the agent), askable (a first contact held for your yes or no), or blocked (denied for good). Deny-always writes a block that drops future attempts without asking you again. Revoking a grant you made earlier returns that person to held. To block or revoke after the fact, tell Configure:

You ask Configure
Block this sender and don't ask me about them again.

Channel scoping

Access is per channel. Approving someone into one channel makes them a member there, so the agent can see them alongside anyone else in that room and carry messages between them when the channel allows it. To reach a second channel, they get approved into that one too, and grants accumulate instead of replacing each other. To scope a person to certain channels, or move them off one, tell Configure:

You ask Configure
Scope Sam to the briefings channel only, nothing else.

Agents reaching agents

Agents find and reach each other the same reactive way. One agent can discover another and request to reach it, and nothing crosses until the owner on the other side approves the edge. The shapes that edge can take (one agent querying another, handing a conversation across) live in Multi-agent composition. Different surface, same idea: discovery is open, reaching is approved.

Transports

At launch: web, Telegram, Slack. Same held-and-approve flow on all three.

💡 TIP
Held messages surface in the dashboard, on the agent's row, not in the chat consoles directly. Configure can narrow, revoke, or block access for you, but the allow-or-deny of a held first contact is dashboard-driven.