{"slug": "hotcrp-com-ai-agents-and-bot-accounts", "title": "Hotcrp.com – AI agents and bot accounts", "summary": "HotCRP.com, the conference management system, now supports AI agents and bot accounts, allowing bot accounts to read submissions, set tags, and write reviews when enabled by administrators. The feature, announced by Eddie Kohler on 19 August 2026, is disabled by default and can be activated via Settings > AI, with permission scopes limiting agent actions and changes logged for security.", "body_md": "# AI agents and bot accounts\n\n**19 August 2026** — HotCRP.com sites can now be connected to AI agents. If\nconference administrators allow it, bot accounts can read submissions, set tags,\nand write reviews, and PC members can connect agents that work on their behalf.\n\nAgents connect over [MCP](https://modelcontextprotocol.io/), the protocol that\n[Claude](https://claude.ai), Claude Code, and other clients use to reach outside\nservices. Agents can currently search submissions, read reviews, comments, and\nsubmitted documents, set tags, and write reviews and comments.\n\nAI agent support is disabled by default. It can be enabled using Settings >\nAI on all HotCRP.com sites, including [test sites](https://test.hotcrp.com/).\n\n## Security and risks\n\nHotCRP sends nothing to any AI service on its own, and connecting an agent is never automatic. But once connected, the submissions, reviews, and reviewer identities read by an agent are sent to the service that runs the agent. Whether the service keeps the data, trains on it, or exposes it to others is between the service operator and the person who authorized the connection. HotCRP doesn’t control that, and a conference’s promise of confidentiality to its authors and reviewers does not automatically extend to AI services.\n\nSponsors and conferences differ on whether confidential submissions may be sent to third-party services at all, and some forbid it. Check your sponsor’s policy before enabling agents.\n\nNote that most AI services have settings that govern how conversations are retained and used. Defaults differ by vendor and by plan, and business plans often differ from personal plans. It’s not always easy to control these settings. Conferences concerned about agent confidentiality should limit AI agent use to administrators.\n\nSubmissions and reviews might also contain text aimed at agents rather than\nhumans. A paper can contain instructions; an agent that can write may be induced\nto follow them. [Scopes](#scopes) bound the damage a rogue agent can do, and\nchanges made by agents are logged.\n\n## Scopes\n\nAI agent permissions are governed by **permission scopes** set at authorization\ntime. A scope limits a credential’s rights. The `read`\n\nscope, for example,\nallows reading, but not writing; an agent with `read`\n\nscope is prevented from\nmodifying conference data. Scopes can also name submissions: the `read#10`\n\nscope\nallows an agent to read submission #10 (including reviews and comments), and\nnothing else; `read#agent`\n\nlets it read submissions with tag #agent, and\n`read?q=dec:yes`\n\nlets it read accepted submissions. (Specifically, it can read\nthose submissions whose acceptance status the connected user can see: scopes do\nnot expose information the connected user couldn’t otherwise view.)\n\nIf a PC member loses a role, or a conference narrows who may use agents, the associated credentials stop working. Users can see and revoke their own agents under Profile > Developer.\n\nScopes relevant for agents include `submeta:read`\n\n(submission fields),\n`document:read`\n\n(PDFs), `tag:read`\n\n, `review:read`\n\n, `comment:read`\n\n, `tag:write`\n\n,\n`review:write`\n\n, and `comment:write`\n\n. A scope like `paper:read`\n\ngrants all of\n`submeta`\n\n, `document`\n\n, `tag`\n\n, `review`\n\n, and `comment`\n\n.\n\n## Bot accounts\n\nAdministrators can create and manage bot accounts designed for agent use. Bots are typically unlisted PC members, with PC rights; they can be assigned reviews, for example. Unlike other accounts:\n\n- Bots sign in\n**only as authorized by conference administrators** using API tokens or OAuth authorization. - Bots are\n**never anonymous** and they are explicitly identified as AI.\n\nCreate bots under Settings > AI.\n\n## Conclusion\n\nAI review is new to our community. Conferences want different things, and the\nset of site features available to agents is still expanding. Please email me\nwith questions, ideas, and bugs, or [use\nGitHub](https://github.com/kohler/hotcrp) to create issues.\n\n— Eddie Kohler", "url": "https://wpnews.pro/news/hotcrp-com-ai-agents-and-bot-accounts", "canonical_source": "https://hotcrp.com/news/2026/ai-agents-202608", "published_at": "2026-08-22 16:46:22+00:00", "updated_at": "2026-08-22 17:14:14.785698+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "ai-policy"], "entities": ["HotCRP.com", "Eddie Kohler", "Claude", "Claude Code", "MCP", "GitHub"], "alternates": {"html": "https://wpnews.pro/news/hotcrp-com-ai-agents-and-bot-accounts", "markdown": "https://wpnews.pro/news/hotcrp-com-ai-agents-and-bot-accounts.md", "text": "https://wpnews.pro/news/hotcrp-com-ai-agents-and-bot-accounts.txt", "jsonld": "https://wpnews.pro/news/hotcrp-com-ai-agents-and-bot-accounts.jsonld"}}