# Getting Started

### To get started with IAM Permissions

<figure><img src="https://1793025303-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeLw7hj1pxE38VmG1sYVW%2Fuploads%2FPesh4wrxYIrixNR7XExw%2F3.gif?alt=media&#x26;token=0b206c31-5ffe-430c-938e-ff7955e28c7a" alt=""><figcaption></figcaption></figure>

1. Navigate to **Settings** in [app.north.cloud](https://app.north.cloud)
2. Select **IAM Permissions**
3. Click **Invite user**
4. Choose the cloud accounts the user can access
5. Assign feature-level permissions
6. Send the invite

New users do not receive full access by default. All access must be explicitly granted during the invite process.

### Update permissions over time

Permissions can be updated at any time as roles change or teams grow.

Admins can:

* Add or remove account access
* Change feature permissions
* Restrict or expand user capabilities

Changes take effect immediately.

### Using IAM Permissions with Agent North

Agent North respects user permissions.

<figure><img src="https://1793025303-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FeLw7hj1pxE38VmG1sYVW%2Fuploads%2FG5XwKkBpKdd3b4alknm3%2F4.png?alt=media&#x26;token=20bd587f-02df-44ee-9975-2c3fdfb61720" alt=""><figcaption></figcaption></figure>

When a user interacts with Agent:

* Agent can only retrieve data the user has access to
* Restricted accounts or features are excluded from responses

If you want to limit what data Agent North can surface for a user, restrict their account or feature access accordingly.

More granular Agent-level controls are planned for future updates.

<br>
