Control access

Decide which resources, models, features and actions the whole organisation, a team or one person may use.

Access answers "who can use what". You set it per person, per resource, or for models and features at three levels: the organisation, a team or one person. Giving access never copies a resource: people work with the original.

Access and Models are open on every plan. Teams need Business or Enterprise.

Access: per person or per resource

Open Access in the Workspace console. Use View access to switch between two views of the same thing.

Pick a team or a person and see what they can use. The Grants tab lets you give or remove access to agents, workflows, actions, skills and rules. Each grant saves straight away and has an Undo. The Role matrix tab shows what each role can do and marks Your role.

Some access has no grant behind it. The page labels it: Owner (the person created it), Via team, or Everyone (shared with the whole organisation). Only direct grants can be changed here.

A grant to a person and a grant to their team add up. You can only grant what you can use yourself, so a team manager is limited to their own resources.

Models

Open Models to choose which AI models the workspace may use. Each model shows an EU or US badge. A model switched off for the organisation disappears for everyone. A team can be restricted further, and a person can be restricted further still, but a model switched off at organisation level cannot be switched back on lower down. A team manager sets this for their own teams.

Features and chat capabilities

Open Features. The first part lists the modules the workspace uses: Chats, Board, Agents, Workflows, Knowledge, Projects, Rules, Skills, Actions and Connections. A module switched off disappears from the menu for everyone; nothing is deleted and switching it on brings everything back. At least one module must stay on.

Below that are chat capabilities you can turn off for the whole workspace, which overrides each member's own chat settings. They include Web search, Image generation, Files, documents & data (with Presentations, Spreadsheets and Documents), Chat memory and Chat sharing. Chat capabilities need the Business plan.

Actions

Actions are what agents and chat can do in connected apps. Under Access, the Actions tab lets you enable or disable each action for teams and individual people. Where an action needs approval, a workspace admin can set the policy: Ask every time, Always allow or Only when important. Only workspace admins can change action policies.