Quick answer
An AI worker is a worker of kind agent on the Workers register. On Agents (/admin/agents, HR admins only) you give an agent a profile — the models, tools and data it may use — then manage its system prompt as numbered versions that a second person approves. Every agent has a kill switch that denies its access at once.
Workforce is in beta. It is listed on the Modules page with no price yet. ASHR.work does not run your agents: it is the register of what each agent is allowed to be and to use.
How do I create an agent profile?
Add the agent as a worker
On the Workers page, add a worker of kind agent with its purpose, accountable owner, supervisor and data classification.Open Agents
An active agent appears in the Create an agent profile list until it has a profile.Set its allowlists
List the allowed models and choose whether they are for production or verification, then list the tools and the data the agent may use. Allowlists are default-deny: anything not listed is not allowed.Set its safety references
Choose a fallback behaviour (refuse, escalate, read only, or queue for a human) and enter an evaluation suite reference and an incident process reference. Both references are required.
How do prompt versions work?
On the agent's page, Propose a new prompt version with the system prompt, the tools and data it uses, and the model that drafted it if one did. A version cannot use a tool or data outside the profile's allowlists, and once proposed it cannot be edited — a change is a new version. ASHR.work records a content hash for every version.
A different active person then selects Approve, which makes that version live, or Reject with a reason. Version history shows which version is live, and Roll back to this version points the agent back at an earlier approved version, with a reason. Nothing is edited or deleted.
What does the kill switch do?
Kill agent asks for a reason, then marks the agent as killed — from that moment every entitlement check for it is denied — and revokes all its active and requested grants. Protected owner access is never revoked. Lift kill switch also asks for a reason, but it does not restore any grant.
Creating a profile, proposing, approving, rejecting and rolling back versions, and killing or reviving an agent are all recorded in the audit log.
Where do I manage what an agent can access?
Grants live on Entitlements: agents get a 90-day default term, and a request for anything high risk needs a second person's approval. Include agents in an access review by leaving the worker kind on "All" or choosing agent.
Frequently asked questions
- Does ASHR.work run my AI agents?
- No. ASHR.work does not run agents. It keeps each agent's record, its approved prompt versions and its access grants, and answers your systems when they ask whether an agent may use a resource.
- Can the person who wrote a prompt version approve it?
- No. A different, active person must approve it. Approval is what makes a version live.
- Does lifting the kill switch give the agent its access back?
- No. Grants revoked by the kill switch stay revoked. Grant the access again on the Entitlements page if the agent still needs it.
This guide also lives in the help centre at /help/admin/ai-workers, which is its canonical home.