Agent access
Owners and admins control what members can do with each agent. Owners and admins always have full access (including delete); these levels apply to members.
Access levels
Section titled “Access levels”| Level | A member can… |
|---|---|
| No access | not see the agent at all — including its saved outputs in the Artifact Library |
| Watch only | open the agent and watch its runs, history and saved outputs (the Artifact Library) — but can’t run it |
| Run only | run and chat with the agent — but can’t edit its configuration |
| Run & edit | run and edit the agent (the default) — but can’t delete it |
Deletion is always an owner/admin action — no member level grants it.
Setting access
Section titled “Setting access”Each agent has a default that applies to all members, plus optional per-member exceptions.
- Open the agent → Overview
- In the Member access panel, choose the default for everyone
- Optionally add a member and give them a different level
Most of the time you set one default and never touch the per-member list.
What members see
Section titled “What members see”- No access agents are hidden from the member everywhere — the agent list, the workspace switcher, the Runs / Live Monitor / Quality views, and the agent’s Artifact Library (its saved charts, documents and other outputs).
- Watch only agents show a Watch only badge; the member can open the agent and follow its runs, but the message composer is disabled.
The default for every agent is Run & edit, so unless you change it, members keep running and editing agents exactly as before.
See also: Roles & permissions · Member governance.

