Skip to content
SHAPP
Request a demoTry for free
Security & control

Delegate the work.Keep the final say.

AI becomes useful when you can trust it with real records. SHAPP gives it boundaries: the right access, authorized actions and approvals where you need them. Your team moves forward. You know who can do what.

Role-based accessAI under delegationAttributable changes

Your business grows.You stay in control.

Your business information matters. You choose who can access it, set limits for Shappy and keep a record of what changes.

Your team
Your software
Shappy
Your rules, everywhere.

For your team, your software and everything Shappy does.

Controlled accessAI you controlActivity history

The right access for the right people.

Your customers, your figures, your records: you decide who can view or change them, based on each person’s responsibilities.

Delegate and stay in control.

Shappy works with the permissions you grant. It follows the same rules as your team and can never access more than you can.

A clear record of what happened.

See what changed and who made the change, including when Shappy acts for you. Follow activity and review it with confidence.

You decide what commits the business

It prepares. You review. Then you give approval.

A customer reminder, an important change or a sensitive operation: define the actions that require approval. Shappy can move preparation forward without deciding the next step for you.

ShappyActing for Sophie Martin
SM

Prepare a reminder for the Laurent invoice. I’ll approve the message before sending.

An identified person
Verified permissions
Your approval before proceeding
SHAPP / Approval center
Customer reminder · Laurent House

Shappy prepares.You have the final say.

A record at every step

Example of an action requiring approval. Rules are defined for your business.

More people. More applications.Still your rules.

Adding a colleague or an AI assistant should not turn your business into a black box. Responsibilities, permissions and approvals need to stay understandable, even as your organization grows.

The right access, in the right place

Your entire team. Different responsibilities.

A manager, a team member and an assistant do not need the same permissions. Switch profiles to see how one workspace can give each of them a useful scope.

SHAPP / Roles & permissions
SM

Sophie Martin

She oversees the business, approvals and team access.

Business manager
In your workspaceThis profile can…
View recordsAll records
Prepare a quoteAllowed
Send to customerAllowed
Change permissionsAllowed

The same access rules, in the app and for AI.

Example permission setup, to adapt to your team’s responsibilities.

Trust is built into the way work happens

Control goes beyond what you see on screen.

Applications and agents rely on RootCX. Controls are applied beneath interfaces, at the data access layer: hiding a button is not the protection mechanism.

01

An identity for every actor.

A person, an agent or a service account acts with an identity. An action can be linked to its author and the authority used.

You know who acts, and for whom.
02

Bounded delegation.

Shappy acts within the permissions you delegate. That delegation cannot exceed the permissions of the person for whom it works.

Delegating a task does not create new powers.
03

A record of changes.

Changes are attributable. Find what changed and understand an agent’s contribution to your activity.

The result and its origin stay connected.
A framework that stays clear

Your business changes. Access follows your decisions.

Starting alone, welcoming a team, delegating more to Shappy: each stage is a chance to adapt permissions to the reality of work.

01

Someone joins.

Define their role, useful records and necessary operations. They find their workspace without getting every permission by default.

The right scope from the start.
02

A role evolves.

Review responsibilities and permissions. Access should follow the current role, not an accumulation of old needs.

Review roles when the organization changes.
03

You delegate a routine.

Identify the owner, expected result and approvals. Shappy receives a work instruction and an explicit scope.

A bounded routine and an identified owner.

Questions to ask before delegating.

Can Shappy bypass a user’s permissions?

RootCX applies controls beneath applications. Delegation is bounded by the permissions of the person for whom the agent acts. Roles, accessible records and authorized operations must be configured for your scope.

Does everything need manual approval?

No. Viewing a record, preparing a draft and sending a customer message have different stakes. Rules define what is authorized within the delegated scope and what requires a human decision.

Can we see what Shappy changed?

The audit foundation attributes changes to their author and distinguishes an agent from the person on whose behalf it acts. The presentation of this history depends on the application scope.

What do we check before sharing records with the team?

Accounts, roles, record access, connections and tasks delegated to Shappy. Hosting, backup and recovery arrangements are also clarified for your offer.

Make room for AI.On your own terms.

Start with a concrete need and the people who need access to it.