top of page

Zia · AI governance

What Can a Zoho AI Agent Actually See?

AI

7 September 2026

6 min watch

Zoho says it in its own AI governance documentation: Zia agents inherit the permissions of the user running them.

Next step

#:##

Chapter Description

In this video.

Zia agents inherit the permissions of the user running them. An agent is not a new security boundary — it is a mirror of the one you already have.

  • If you've turned on Zia agents in Zoho CRM, here's a question worth asking before anyone else does: what can that agent actually see?

    Not what it's supposed to do. What it can reach.

    The answer surprises most teams, and it has nothing to do with the AI. In the next few minutes I'll show you where the boundary really lives, why most mid-market orgs have it set wider than they think, and the three things to check this week.

    Everything on screen is a mock demo of Zoho CRM with sample data.

    This is a mock demo of Zoho CRM — the Leads list you'd see every day. Names, companies, job titles, email addresses. Behind them, on each record, there's usually more: deal values, notes from calls, sometimes personal detail a rep typed in without thinking about who'd read it later.

    Now add an agent. You ask it a plain-English question — "which leads went quiet this month?" — and it answers in a second. It feels like a search box that got smart.

    It isn't. It's a user. And that changes the question from "what did I ask it" to "what is it allowed to open."

    Zoho is explicit about this, and it's the one sentence that decides everything downstream. From their own AI governance documentation:

    "Every AI feature — predictions, recommendations, and even agents — inherit these same permissions, which ensures your AI features can only access and act on data that the user leveraging these features is allowed to see."

    Read that as good news, because it is. The agent isn't a hole in your security model. It's a mirror of it.

    Which means: whatever your permissions look like today, that's the agent's reach.

    So let's look at where that boundary is actually defined. Setup, Security Control, Profiles.

    A profile is a set of permissions. Zoho ships two: Administrator and Standard. Administrator can see everything and change everything. Standard is narrower.

    Here's the pattern we see constantly in mid-market orgs. Look at the user list. Count how many are on Administrator.

    It's rarely one. Usually it's most of them — because somewhere in year one, someone hit a permission wall on a Tuesday, and the fastest way past it was to make that person an admin. Nobody ever went back.

    That was a manageable amount of sloppiness when a human had to click through screens to find something. A person who technically can open the Deals module mostly doesn't, because they have no reason to.

    An agent has a reason. It reads everything it's permitted to read, every time, in a second, because that's the job you gave it.

    The permission you never tightened just became the permission that gets exercised.

    Profiles are the outer wall. The finer control is at field level.

    Inside a profile, on any module, you can set individual fields to read-only or hidden. This is where the sensitive things live — a discount ceiling, a margin field, a note field somebody's been using as a diary.

    Here's the demo. Same mock CRM, same question, two different users.

    First, running as an administrator. The agent returns the lead, the pipeline value, and the internal note.

    Now the same question, same agent, running as a Standard user with the margin field hidden. Different answer. The number is gone, because the field it needed was never visible to that user.

    Nothing about the agent changed. The only thing that changed was who asked.

    That's the control. It was always the control. Most teams have just never tested it.

    One more control, and almost nobody knows it's there.

    Still inside the profile, under Setup Permissions, there's a section called Zia. Every AI feature has its own switch here — recommendations, predictions, Ask Zia, the writing assistant.

    And near the bottom, one called Models.

    Open it. That is the list of model providers this profile is allowed to use. Zoho's own hosted model, and then the outside ones. On a default Administrator profile, all of them are ticked.

    So the question isn't only what your data is, and who can see it. It's which company's model your CRM records are allowed to travel to — and that is a checkbox, on a screen, that somebody in your org already has the rights to change.

    Second question, and it's the harder one: if an agent did reach something it shouldn't have, how would you know?

    Zoho keeps audit logs — who did what, what changed, when. Agent activity lands there like any other activity.

    But a log only helps if someone reads it. And "someone reads it" is a job with a name on it, or it doesn't happen.

    This is the part that isn't a settings screen. Governance isn't a toggle you flip. It's three questions with owners:

    Who decides which agents get turned on.
    Who reviews what they did.
    And what happens when one does something it shouldn't.

    Gartner expects more than forty percent of agentic AI projects to be cancelled by the end of 2027 — and one of the reasons they cite is agents behaving in ways that violate policy. That's not a model problem. That's this problem.

    So here's what to do this week. Three things, none of them takes long.

    One. Open Setup, Security Control, Profiles, and count your administrators. If it's more than a couple of people, you don't have a permission model — you have a habit. Write down who genuinely needs it.

    Two. Pick your most sensitive field. Margin, discount, compensation, whatever it is in your business. Check which profiles can see it. Not which should — which can. There's usually a gap.

    Three. Before you turn on your next agent, ask which user it runs as, and then go look at what that user can open. If nobody in the room can answer that in under a minute, that's your finding.

    None of this is AI work. It's the unglamorous middle layer — permissions, ownership, someone accountable. It's the work that decides whether the AI part pays off at all.

    The agents aren't the risk. The unexamined permission model underneath them is, and it was there before anyone said the word AI.

    The good news is it's fixable in an afternoon, and the fix makes everything else you do in Zoho better.

    If you want a second set of eyes on yours, that's the kind of thing we do — we're CodeStringers, a Zoho-centered consultancy in Santa Cruz.

    Subscribe if this was useful. There's more coming on getting the foundations right before the agents go on.

Next step

What this covers.

An agent is not a new security boundary | What is loose in your profiles today is an agent's reach tomorrow | Setup / Zia / Models is the screen nobody opens

At a glance

Runtime

5:30

Published

7 September 2026

Also on YouTube - subscribe for weekly videos.

integrated business solutions

One partner. Better outcomes.

We hold accountability for the whole system — not one app, and not one project.

bottom of page