Manage AI Agent Access
Who Has Access
AI agent access follows dashboard access. Everyone who has opened your app’s Expedited WAF dashboard through Heroku is a member of that app, and any member can connect an agent (see Connect AI Agents to Your WAF (MCP)).
An agent sees exactly what its user can see: the WAF services that person can reach from their own dashboard, and nothing more. Agents can view and manage the same WAF settings the member can change in the dashboard: IP and path rules, traffic and caching rules, content security, protected pages, and origin servers. They cannot change your plan, manage certificates, or remove the service. Every change an agent makes is recorded in your Audit Log with the name of the member whose agent made it.
When Access Pauses Automatically
Agent access follows your Heroku access to the app. On every request it is rechecked against your live Heroku app list, so if you are removed from the app on Heroku, or otherwise lose access to it, your agents stop reaching that app’s WAF service within about a minute. There is nothing to revoke by hand.
As a backstop for older grants made before a Heroku account was linked, access also pauses for any member who has not signed into the dashboard in 90 days, so a former teammate’s agent cannot keep access indefinitely. One dashboard sign-in through Heroku refreshes it.
Blocking a Member’s Agent Access
You can block agent access for any member, including yourself, from the MCP page in your dashboard:
- Open your WAF dashboard and go to the MCP page.
- Find the member in the list.
- Click Block. Unblocking works the same way.
Any member can block any member. There is no separate admin role for this.
What Blocking Does and Does Not Affect
Blocking applies to agents only, and only for that app:
- The member’s AI agents can no longer reach that app’s WAF service.
- The member’s own dashboard access is unchanged. They can still sign in and work normally.
- Their agent access to other apps is unchanged.
Disabling Agent Access Entirely
If you want AI agent access switched off for your whole account, contact us at support@expeditedsecurity.com and we will disable it account-wide for you.