The right access for the right people.
Your customers, your figures, your records: you decide who can view or change them, based on each person’s responsibilities.
AI becomes useful when you can trust it with real records. SHAPP gives it boundaries: the right access, authorized actions and approvals where you need them. Your team moves forward. You know who can do what.
Your business information matters. You choose who can access it, set limits for Shappy and keep a record of what changes.
For your team, your software and everything Shappy does.
Your customers, your figures, your records: you decide who can view or change them, based on each person’s responsibilities.
Shappy works with the permissions you grant. It follows the same rules as your team and can never access more than you can.
See what changed and who made the change, including when Shappy acts for you. Follow activity and review it with confidence.
A customer reminder, an important change or a sensitive operation: define the actions that require approval. Shappy can move preparation forward without deciding the next step for you.

Prepare a reminder for the Laurent invoice. I’ll approve the message before sending.
Example of an action requiring approval. Rules are defined for your business.
Adding a colleague or an AI assistant should not turn your business into a black box. Responsibilities, permissions and approvals need to stay understandable, even as your organization grows.
A manager, a team member and an assistant do not need the same permissions. Switch profiles to see how one workspace can give each of them a useful scope.
She oversees the business, approvals and team access.
| In your workspace | This profile can… |
|---|---|
| View records | All records |
| Prepare a quote | Allowed |
| Send to customer | Allowed |
| Change permissions | Allowed |
The same access rules, in the app and for AI.
Example permission setup, to adapt to your team’s responsibilities.
Applications and agents rely on RootCX. Controls are applied beneath interfaces, at the data access layer: hiding a button is not the protection mechanism.
A person, an agent or a service account acts with an identity. An action can be linked to its author and the authority used.
Shappy acts within the permissions you delegate. That delegation cannot exceed the permissions of the person for whom it works.
Changes are attributable. Find what changed and understand an agent’s contribution to your activity.
Starting alone, welcoming a team, delegating more to Shappy: each stage is a chance to adapt permissions to the reality of work.
Define their role, useful records and necessary operations. They find their workspace without getting every permission by default.
Review responsibilities and permissions. Access should follow the current role, not an accumulation of old needs.
Identify the owner, expected result and approvals. Shappy receives a work instruction and an explicit scope.
RootCX applies controls beneath applications. Delegation is bounded by the permissions of the person for whom the agent acts. Roles, accessible records and authorized operations must be configured for your scope.
No. Viewing a record, preparing a draft and sending a customer message have different stakes. Rules define what is authorized within the delegated scope and what requires a human decision.
The audit foundation attributes changes to their author and distinguishes an agent from the person on whose behalf it acts. The presentation of this history depends on the application scope.
Accounts, roles, record access, connections and tasks delegated to Shappy. Hosting, backup and recovery arrangements are also clarified for your offer.
Start with a concrete need and the people who need access to it.