This article is auto-synced from its in-app version in Tai.
Company admins only. This page is part of Settings, visible to users with the Company Admin role.
The Web access page decides whether your agents may search and read the public web, and which sites they may reach.
When you'd use this
Use it when an agent needs current information that isn't in your own systems — a government travel advisory, an airline's baggage rules, a supplier's published terms. For example: you want your agents to check official advisories but nothing else, so you list the advisory sites and leave everything else out.
Steps
In the Workbench sidebar, click Settings.
Under AI & Data, click Web access.
Use Allow agents to use the web to turn web access on or off for the whole workspace.
Under Allowed sites, click Add allowed site and type a site, one per row (for example
iata.org). Leave the list empty to allow any site.Under Blocked sites, click Add blocked site and type the sites your agents may never reach.
Click Save changes.
Tips and limits
The workspace switch wins. With Allow agents to use the web off, no agent can search or read a web page, even one whose own web permission is on. Turning it off keeps your lists — turning it back on restores them exactly as they were.
An empty allowed list means the open web, minus your blocked sites. As soon as you name one allowed site, the list becomes the only web your agents can reach.
Blocked wins over allowed. A site in both lists is blocked.
Matching is exact, and covers the
www.form.iata.orgmatchesiata.organdwww.iata.org, but notdata.iata.org— list each host you need. Wildcards like*.iata.orgare not accepted, because a page can redirect and only an exact list can be checked again at every hop.Write bare host names, like
example.com— nohttps://, no path, no port.Nezasa blocks a short list of link shorteners for every workspace. They're shown on the same page, and you can't allow them: a shortened link hides where it actually leads, so an agent following one could leave the sites you allowed.
A refused site doesn't sink the task. The agent is told the site is outside your policy and asked to use a different source.
An agent still needs its own web permission. This page sets the outer limit for the workspace; whether a given agent uses the web at all is part of that agent's own configuration.
Related

