<!--
  Translated by the docs agent from content-src/es/guides/control-del-agente/04-como-encaja-con-las-claves-de-api.md
  (source_hash 3a97a9329255). If that Spanish source_hash changes, re-check this translation.
-->

The "With their API keys" section of a member's record (section 3.2) narrows what **any key that member
creates from now on** can end up doing — it's the **ceiling** for their future keys. The "What this key can
do" picker that person sees when creating a specific key (Manual 50, section 7) can only narrow **within**
that ceiling, never exceed it. Keys that member had already created **before** this narrowing don't change
— a key's permissions are sealed the moment it's created (Manual 50, section 2).