MAEUM BLOG · AI adoption

AI Permission Design — 20 Permissions for What Employees, AI and Agents Are Allowed to Do

2026-09-08 · MAEUM — an AI engineering company that publishes its prices
The first principle of AI permission design is not "can use / can't use" but "what, and how far". With the same ChatGPT, executives use it briefly for briefings while new hires use it deeply to produce documents (OpenAI 2026 paper). So permissions have to be split into twenty and written in three columns — people · AI · agents. The default is simple: AI gets "read + draft"; the other eighteen belong to people. From there you widen one at a time. MAEUM fills in this matrix with you in scoping session 3, and on SaaS (managed) (build from ₩700K + ₩490K / ₩990K / ₩1.49M/mo) permission changes are included in the monthly fee.

Why "can use / can't use" isn't enough

One scene from the OpenAI paper. Inside the same company, new hires send 8–9 more messages per week and executives send fewer than average. Executives ask briefly about topic overviews, fact-checks, legal and finance; new hires produce documents, code and email drafts. They're using the same tool in completely different ways.

So a single line — "all employees permitted to use ChatGPT" — decides nothing. Whether a new hire's draft can go straight to a customer, whether company revenue data can go into an executive's finance question, whether AI can change the booking system directly — these are all different questions.

That's why we split permissions into twenty. It looks like a lot, but they're things you already decide when hiring one human employee. Ask the AI the same questions.

The 20 permissions — five groups

GroupPermissionsAI default
Touching data (5)Read · Create · Edit · Delete · DownloadRead O · Create (draft) O · Edit △ · Delete X · Download X
Moving data (3)Share · External send · Customer contactAll X (a person presses send)
Execution and sign-off (5)Execute · Approve · Sign off · Purchase · ContractAll X
Access (5)Systems · Data · Models · Tools · AgentsOnly what's listed (no default list = no access)
Time and delegation (2)Temporary permission · Delegate/revokeTemporary requires an expiry · Revoke must be immediate

The reason the defaults are conservative is simple. You can always widen later, but narrowing after an incident is too late. Run the first month on "read + draft" only, and widen one cell at a time as the human edit rate drops.

The three-party matrix — why people, AI and agents are written separately

Even "AI" has to be split in two.

The matrix looks like this. Twenty rows × three columns, O/△/X in each cell.

PermissionPerson (owner)AI (conversational)Agent (executing)
ReadOOO (designated scope)
CreateOO (draft)O (draft)
EditO△ (suggest only)△ (after human check)
Customer contactOX△ — this is the fork
ExecuteOX△ — only what's reversible
Sign off · Purchase · ContractO (within limits)XX
DeleteO (after approval)XX

The two highlighted cells are where every company deliberates longest. May the agent text customers directly? May it place orders? The answer comes from the three criteria in Part 3 (is it reversible · who gets hurt if it's wrong · is it judgment or processing).

Clinic scenario — the permission table for a booking-confirmation AI

Say a clinic decides "let AI send tomorrow's patients their confirmation texts." The permission table comes out like this.

This one table becomes the first page of a clinic CRM build (Korean). The system is built to this table, and what isn't in the table the system can't do.

When permissions change — keep just three things

On MAEUM SaaS (managed), permission-table changes are included in the monthly fee. No separate quote for widening or narrowing — that's what makes you actually adjust it.

Sources — what the paper says / MAEUM's extension

MAEUM list prices — VAT excluded · starting prices · final price confirmed after scoping
Scoping pass (5 sessions)₩250K (≈ $179) · up to 90 min each · working demo included
SaaS · managed (recommended)Build from ₩700K (≈ $500) + ₩490K / ₩990K / ₩1.49M/mo (≈ $350 / $707 / $1,064) — servers, AI, improvements, new features and a monthly report included. No per-seat pricing.
SI · ownershipBuild from ₩2.5M (≈ $1,786); full build from ₩7M+ (≈ $5,000+) — no monthly fee afterwards, care passes when needed

KRW is authoritative; USD figures are approximate. SEO and AI-search visibility work is included in every build at no charge. The demo is free — try it, and sign only if you like it.

Frequently asked questions

Twenty is too many. Can we reduce it?
You can start with just the five groups — touching data / moving data / execution and sign-off / access / time. Decide O/X per group, and refine only the rows you need while running the first seat. You don't need all twenty rows on day one.
Does the ChatGPT Enterprise admin panel have these permissions?
Some (who can log in, which features are on). But task permissions like "may it text customers" or "may it place orders" don't exist in any AI vendor's console. They have to be decided on the company-system side.
Isn't giving agents execution rights dangerous?
We don't give irreversible execution (payment, deletion, contracts). Reversible execution (sending drafts, temporary saves, notifications) starts with human confirmation and widens automatically as the edit rate drops. The risk isn't the permission itself — it's granting it without a reversal mechanism.
Who manages the permission table?
The task owner drafts it and the owner of the business confirms it. Reflecting it in the system is our job. On SaaS (managed) that's included in the monthly fee, so just tell us when you want to change it.
What does it cost?
Writing the permission table is included in session 3 of the ₩250K scoping pass. Building the system: SaaS (managed) from ₩700K + ₩490K / ₩990K / ₩1.49M/mo (no per-seat pricing); SI (ownership) from ₩2.5M. VAT excluded.

See it working before you decide

Tell us what you do and what you need. We'll show you a working demo first — the demo is free.