Manage AI Agent Access

Who Has Access

AI agent access follows dashboard access. Everyone who has opened your app’s Expedited WAF dashboard through Heroku is a member of that app, and any member can connect an agent (see Connect AI Agents to Your WAF (MCP)).

An agent sees exactly what its user can see: the WAF services that person can reach from their own dashboard, and nothing more. Agents can manage IP allow and block rules, clear the CDN cache, and manage origin servers. They cannot change your plan, manage certificates, or remove the service. Every change an agent makes is recorded in your Audit Log with the name of the member whose agent made it.

The 90-Day Sign-In Rule

Agent access pauses automatically for any member who has not signed into the dashboard in 90 days. This keeps former teammates’ agents from retaining access indefinitely.

A single sign-in refreshes it: the member opens the dashboard from Heroku and their agent access resumes.

Blocking a Member’s Agent Access

You can block agent access for any member, including yourself, from the AI Agents page in your dashboard:

  1. Open your WAF dashboard and go to the AI Agents page.
  2. Find the member in the list.
  3. Click Block. Unblocking works the same way.

Any member can block any member. There is no separate admin role for this.

What Blocking Does and Does Not Affect

Blocking applies to agents only, and only for that app:

  • The member’s AI agents can no longer reach that app’s WAF service.
  • The member’s own dashboard access is unchanged. They can still sign in and work normally.
  • Their agent access to other apps is unchanged.

Disabling Agent Access Entirely

If you want AI agent access switched off for your whole account, contact us at support@expeditedsecurity.com and we will disable it account-wide for you.