Automatically enabled when you configure UniFi permissions in your agent workflow. No manual toggle needed.
What It Does
- List the consoles and sites the connected account manages, and every device across the fleet with its online state
- Read ISP latency, packet-loss, throughput and uptime per site
- Read a site’s adopted devices with live statistics, and the clients connected to them
- Restart a device or power-cycle a PoE port (always behind technician approval)
- Generate hotspot vouchers; authorize or revoke guest access for a client and delete vouchers (always behind technician approval)
- Read and change networks/VLANs, SSIDs, WANs, VPNs, DNS policies, firewall policies and ACL rules (writes always behind technician approval)
Permission Groups
Each group has an access level: Disabled, Read Only, or Read/Write (Consoles & Sites only ever offers Read Only).
Access Profiles
Read Only
Read Only
All groups Read Only. The agent can look up any resource but never changes anything.
Helpdesk
Helpdesk
Hotspot Vouchers and Clients at Read/Write — issuing a voucher runs autonomously; authorizing a guest still requires technician approval on every call. Everything else Read Only.
IT Admin
IT Admin
Every writable group at Read/Write, but every write requires technician approval — not just the mandatorily-forced ones.
Full Automation
Full Automation
Issuing vouchers runs autonomously. Device actions, network/firewall changes, guest authorization and voucher deletion still always require technician approval — that override is never optional.
Safety Controls
How to Configure
1
Connect UniFi
Save your Site Manager API key in the Neo Dashboard under the Networking integrations category. See Connecting UniFi to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or customize each permission group.
3
Set approval requirements
Every write except issuing a hotspot voucher already requires technician approval; decide whether voucher issue should too.
