Your setup pack ← All 5 docs
Doc 5 of 5 · Access Playbook

Get Your Agent — Access Playbook

This one's yours to read — then just ask your agent to do these things in Telegram. No copying, no pasting. It's a guide for you, not data for the agent.

Open the doors to your agent, one at a time — the safe way. Your Owner Profile and Intake already told your agent who you are. This guide is about giving it access to your email, socials, and tools — safely, in the order that earns trust. Read it, then grant access one door at a time whenever a task needs it.

Why categories, not platform names: every owner has email, socials, somewhere they buy or sell, and one system they live in. The category is universal; the platform recipe inside is just your flavor. If your platform isn't listed, your agent researches its exact grant path and brings you the ready-to-click steps — a missing recipe is the agent's task, never your homework.

Card anatomy: why this category + what your agent will do → platform recipes (exact clicks where we have them) → the research-it-yourself fallback.


CARD 1 — EMAIL — the first ask (an access ladder, not a wall)

Why first: everyone has it, it starts read-only, and it's the fastest personal win — your agent helps YOU before it touches the business. Once granted, your agent can: flag the important email sitting unread before it costs you · brief you each morning on today's meetings · draft replies for your review · file and fetch documents without asking you for links. Two accounts are normal. Most owners run a work address and a personal one. Grant them separately, in either order — your agent keeps them strictly apart and tells you which account anything came from.

This card is a LADDER — four rungs, easiest first. Start on rung 1 today; climb only when a win makes you want more. (Design rule for every rung: the agent does the complicated part; you only click Allow.)

Rung 1 — App password (mail only) — the default first ask, ~3 minutes

An app password is a special extra password Google invents for you. It opens ONLY your mail. It is not your real password, it can't change your account, and you can kill it any time with one click. Here is every click:

  1. On your phone or computer, go to myaccount.google.com (you'll see your own Google account page — your name and photo at the top).
  2. Tap Security in the menu. Scroll to "How you sign in to Google." If 2-Step Verification shows OFF, turn it on first (Google walks you through it — it texts your phone a code). App passwords only exist after this is on.
  3. In the Security search bar at the top, type "App passwords" and tap the result. (Google hides this page — searching for it is the reliable way in.)
  4. Where it asks for an app name, type anything you'll recognize — e.g. "my agent" — and tap Create.
  5. Google shows a yellow box with a 16-letter code in groups of four (like: abcd efgh ijkl mnop). That's the app password. It is shown ONCE.
  6. Give that code to your agent the safe way it tells you (it will name the exact place — never just paste it into a public chat). Your agent stores it locally, never shows it to anyone, and tells you where it lives.
  7. How you know it worked: by tonight your agent shows you your first inbox triage — the emails that matter, the ones that don't, drafts waiting for your review.

Revoke (one click): myaccount.google.com → Security → search "App passwords" → tap the trash icon next to "my agent". The code dies instantly; nothing else about your account changes. (Outlook: Microsoft account → Security → Advanced security options → App passwords. Yahoo: Account Security → Generate app password.)

Rung 2 — Browser session (calendar + Drive quick win, zero setup)

"Log into Google on the agent's browser" means exactly this — nothing more:

  1. Your agent runs on a computer, and on that computer it has its own web browser.
  2. Your agent opens google.com's normal login page in that browser and shows it to you.
  3. YOU type your email and password yourself, right into that screen. The agent never sees the password, never stores it, never types it. If Google texts a code to your phone, you enter that too.
  4. Once you're signed in, the agent works inside that logged-in window: reading today's calendar for your morning briefing, fetching the Drive file you asked for.
  5. How you know it worked: ask it "what's on my calendar tomorrow?" — it answers with your real events.

Revoke (one tap, from your phone): Google app (or myaccount.google.com) → Security"Your devices" → tap the agent's session → Sign out. ⚠️ Only ever do this on the agent's OWN machine — never on a shared or public computer, and never by sending your password in chat "just this once."

Rung 3 — Give your agent its own email (the tidy upgrade — optional)

  1. Create a free Gmail for your agent, once (~2 minutes)
  2. Share to that address with exact roles: Calendar → "See all event details"; Drive folders → Viewer (Editor later if you want filing done)
  3. Gmail → Settings → Accounts → "Grant access to your account" (delegation)

Revoke: unshare / remove delegation. One click each.

Rung 4 — Full OAuth (the power setup, when you're ready)

Your agent PREPARES the entire setup as ready-to-click instructions — every screen, every field, every value to paste — and hands them to you. YOU click through it yourself, approving scope by scope; nothing exists until your clicks create it. Revoke: Google Account → Security → Third-party access → remove. One click.

Provider not here? Tell your agent what you use — it researches the exact grant path and brings you the steps. What email access CANNOT do (any rung): change your password, see accounts you didn't grant, or send anything outside the rules you set.


A pattern you'll meet below: the logged-in session

Personal accounts (your own Facebook, Instagram, your Shopee buyer account) have no "add a team member" button — they were built for one human. The safe pattern:


CARDS 2 & 3 — SOCIAL MEDIA #1 and #2

One template, used twice: your main platform first, the second after the first win.

Why this tier: visible value — drafts, replies, alerts — with no money exposure. Once granted, your agent can: watch your DMs and comments and flag the ones needing a human · draft posts and replies for your review · summarize what happened across your accounts each day · report weekly on what's actually working.

Lead recipe — YOUR personal Facebook / Instagram / TikTok:

  1. Your agent opens the site in its own browser and hands you the keyboard — you log in yourself (the logged-in-session pattern above)
  2. Tell it what it may do there: watch DMs, draft replies for your ok, summarize your feed/comments — drafting is fine; posting still waits for your word each time
  3. Check the session appears under Settings → "Where you're logged in" on your phone

Revoke: log out that session from your phone. One tap, instant.

Later recipe — Facebook Page + Instagram via Meta Business Suite:

  1. Meta Business Suite → Settings → People → Add People → agent's email
  2. Assign your Page + IG account with partial access (content/community roles — no ad accounts, no billing)
  3. Send the invite

Revoke: Business Suite → Settings → People → remove. Instant.

LinkedIn: personal profile = logged-in session. Company page: Page → Settings → Manage admins → add as Content admin (not Super admin). X (Twitter): Settings → Security and account access → Delegate → invite as Contributor (not Admin). YouTube: YouTube Studio → Settings → Permissions → invite as Viewer or Editor (not Manager).

Platform not here? Your agent researches it and brings the exact steps. What this tier CANNOT do: post publicly without your word, take over the account, remove you, or touch billing.


CARDS 4 & 5 — PURCHASE PLATFORM(S) — where you buy, and where you sell

Main platform first, second after the first win. Most owners start on the BUYER side.

Lead recipes — your BUYER account (Shopee / TikTok / Lazada / Amazon as a consumer): Once granted, your agent can: track every order and tell you what's arriving when · flag a stuck delivery · watch items you want for price drops and vouchers · keep your purchase history organized for claims and reorders.

  1. The logged-in-session pattern: agent's browser, YOU type the password
  2. Tell it what to watch: open orders, deliveries, a wishlist for price drops
  3. Confirm the session shows in the app's active-sessions list on your phone

Revoke: log out that session from your phone. One tap.

Seller recipes (when you also SELL — granted after the buyer-side win): Shopee Seller Centre: Seller Centre → Shop Settings → Sub-account Management → add a member with the agent's email; role ticking only Orders + Products (Finance and Settings stay unticked). Revoke: Deactivate. Instant. TikTok Shop: Seller Center → My Account → Sub-account → view-level on Orders + Products. Lazada: Seller Center → Settings → Manage Users → role limited to Orders/Products viewing. Shopify: Admin → Settings → Users and permissions → Add staff → tick only Orders + Products (+ Reports). WooCommerce / WordPress: WP Admin → Users → Add New → Role: Shop Manager (NOT Administrator). Amazon Seller Central: Settings → User Permissions → view rights on Orders + Inventory only.

Platform not here? Your agent researches it and hands you the exact steps. What this tier CANNOT do: buyer side — buy anything or touch payment methods; seller side — change prices, edit listings, refund anyone, or touch payouts.


CARD 6 — YOUR DAILY WORK PLATFORM — the system you actually live in

Your own website, an ERP, a booking system, a POS, your accounting tool — whatever runs your day. No card can pre-carry every recipe here, so this card teaches the PATTERN, and your agent does the platform homework.

The pattern — every grant, every platform, no exceptions:

  1. Least-privilege role, by name. Your agent asks for the lowest tier that does the job — and names it.
  2. A credential that is only the agent's. Its own login, a sub-account, a scoped key — or the logged-in-session pattern. Never a shared login handed over in chat, never an OTP.
  3. Can/can't, stated up front. Before you grant, your agent tells you exactly what it will do and what that level cannot do.
  4. One-click revoke. If you can't kick it out in one click, the grant is designed wrong — your agent proposes a different route.

Late-tier recipes that live here when the owner uses them: Klaviyo: Settings → Account → API Keys → Create Private API Key → Custom → read-only on Campaigns, Flows, Metrics. Revoke: delete the key. Meta / Facebook Ads (money — always the LAST ask): Business Settings → People → agent's email → ad account with the Analyst role (view performance only — cannot create/edit/pause ads, change budgets, or spend a cent). Revoke: remove.


The rule that never changes, on every card — three kinds of secrets, three different answers:

  1. Your REAL password (and any login code texted to you): your agent never asks for it, never holds it, never types it. Where a personal account needs a login, YOU type it yourself on the agent's machine — and your phone's active-sessions list is always the kill switch.
  2. Scoped credentials you grant on purpose — an app password, a sub-account, a limited API key: yes, your agent keeps those, stored locally in a place it names to you, never shown in chat — and each one comes with its one-click revoke.
  3. If any agent ever asks you to just send your real password — something is wrong; don't, and tell us.

Get Your Agent — set up for you.

👉 How to use it: read it, then hand your agent the tasks in plain English — e.g. "summarise my inbox", "watch my store for stuck orders". It just works.
Want more than setup? This pack gets your agent working for you. The upgrade — teaching it to remember you across every session and run as a disciplined super-agent — is Agent Dojo, a separate, bigger step beyond Get Your Agent. → aiagentdojo.com

That’s the last one — your agent now works the way you do.

Get Your Agent · your setup pack · questions? [email protected] — a human answers.