Zia · AI governance
Whose Model Is Reading Your Pipeline? | Zoho Zia Permissions And Model Provider Governance
AI
12 September 2026
5 min watch

Every Zoho AI feature inherits the permissions of the person using it. That is the question everyone asks. Here is the one nobody does.
in this video
0:00
The half nobody is looking at
0:47
Zoho's own words on where the model comes from
1:33
The unit of the decision is the profile
2:15
The page itself
3:11
Three questions, answerable this week
3:58
In this order
In this video.
What a Zoho AI feature can see is documented and settled. Whose model does the reading has a default, set per profile in CRM and per agent at creation, and almost nobody has opened the page where it lives.
If you have switched on any of Zoho's AI features, you have probably already asked the first governance question. What can this thing see? And Zoho answers that one plainly: every AI feature inherits the permissions of the person using it. An agent sees what its user sees. That is documented, and it is true. So here is the question almost nobody asks. Whose model is doing the reading? Because when an agent summarises a deal, some model, belonging to some company, processes the text of that deal. Which company, and under what arrangement, is a decision. It has a default. And you can change it. Everything on screen is a mock demo of Zoho CRM with sample data. Start with Zoho's own documentation, describing how an agent gets its model. If you enable the ZKS option, you can use the default LLMs and choose between Zoho and OpenAI under Vendor Configuration while creating the agent. Worth reading twice, because there are three separate facts inside one sentence. There is a default. The default is not the only option. And the choice is made per agent, at the moment somebody creates it. That last part is the one with consequences. It means the decision belongs to whoever is building agents, on the day they happen to build one. Not to a policy, and probably not to a conversation. The same documentation describes a second route. Bring your own key: use your own account with a model provider directly. Which is a different data path, a different contract, and a different company. Now the other half, and this one is inside CRM. This is the profile list. Zoho ships two: Administrator and Standard. That matters here because the AI settings we are about to open are set per profile. Not per person. Not per agent. Per profile. So the number of distinct AI postures available to you is the number of profiles you have actually built. If you have two, you have two. Everybody in a profile gets whatever that profile gets, and the only way to give your finance team a different arrangement from your sales team is to have given them different profiles first. A third profile costs nothing. It is configuration, not licensing. It just has to occur to somebody before the AI settings do. And this is the page. Setup permissions, Zia, for a single profile. Every AI capability in the product is a row here, with a switch. You can turn an individual feature off for one profile and leave it on for another. That is considerably more control than most people assume they have, and it is why this page is worth ten minutes of somebody's attention. The practical version of that is worth saying out loud. You can give a profile an assistant that reads and drafts, and withhold the features that write back. Same product, same licence, two different postures, decided on this page. The row to find is the one labelled Models. That row is where the model providers permitted for this profile are governed, and it is the join between the two halves of this video. What the feature can see, and whose model gets to see it. Most estates have never opened this page. Not because it is buried. It is three clicks from Setup. Nobody was ever given the decision. So, three questions. All three are answerable this week, without a project. One. For each profile, which AI features should exist at all? Not which ones are useful. Which ones are appropriate for the people who hold that profile. Two. For each profile, which model providers are permitted? That is a data question. Depending on what industry you are in, it may also be a contractual one, and it is not a question your Zoho administrator should be answering by themselves on a Tuesday afternoon. Three. Who owns those two answers? A person, by name, who revisits them when Zoho ships a new AI feature. Which is currently happening faster than any review cycle you have. If the third answer is nobody, the first two will drift. And they will drift toward on. Concretely, and in this order. Open the profile list and count them. If the answer is two, that is your real constraint, and building a third profile is a prerequisite rather than an improvement. Open the Zia permissions page for each profile and read it top to bottom, once. Out loud, if that helps, because the switches are easier to argue about when somebody says them. Then go and find out which vendor configuration your existing agents were actually created with. Not what your policy says. What the agents say. Somebody chose, on some particular day, and it is worth knowing what they chose before you decide whether it was right. The known half of this is settled. An agent sees what its user can see, Zoho documents it clearly, and it is worth trusting. The half nobody is looking at is whose model does the reading. That one has a default, and a default is a decision somebody else made on your behalf. We are CodeStringers. We implement, integrate and operate Zoho-centered business systems, and permission models are the thing clients most often ask us to look at shortly after they have switched something on. If you do one thing after this: open Setup permissions, Zia, and read a single profile. Ten minutes. It will tell you whether anyone has been here before you.
Next step
What this covers.
- Zoho's own documentation says you can use the default LLMs and choose between Zoho and OpenAI under Vendor Configuration while creating the agent, so there is a default and it is not the only option
- AI settings are per profile, so the number of profiles you have built caps the number of AI postures available to you
- The Models row under Setup / Setup Permissions / Zia governs which model providers a profile may use, and is three clicks from Setup
At a glance
Runtime
5:16
Published
12 September 2026