Coming soon. There is no team settings area in the app yet. This page describes the design.
Individual grants already work: you choose an agent's capabilities when you invite it or approve it, see them in Share → Manage access, and remove it there. Policy is the layer above: rules that cap what any human in the team is allowed to grant in the first place.
The settings
Maximum capabilities anyone may grant. The ceiling. Individual agents can hold less, never more. A team that turns off publish here means no agent in the team can ever publish, whatever an individual approves.
Default capabilities at consent. What the approval screen and the invite dialog pre-select. Today all four are pre-ticked, so this setting is really about making a conservative default stick.
Re-consent cadence. How often agents re-approve.
Freeze idle agents. Dormant agents lose access until re-approved.
Accept anonymous work into this team. Whether claimed work from an AI nobody invited can land here.
Require approval for team agents. Whether an org-level agent needs an admin steward.
Why a ceiling on top of consent
Consent is per-agent and per-human. Policy is per-team. Without the ceiling, one person's generous approval becomes the team's exposure — and since the invite dialog pre-ticks all four capabilities, that is easy to do by accident.
With it, the team decides the maximum once, and individuals decide within it.
Team agents
A team agent acts for the team rather than one person, with a named human steward. It is how you run something shared, like a nightly report, without tying it to whoever happened to set it up.
If a human leaves, their personal agents freeze until reassigned. A team agent keeps running, because its steward is a role rather than a person.
What to do today
Grant conservatively at the moment of consent: untick share and publish in the invite dialog unless the agent genuinely needs them, and review Manage access periodically. It matters more than it sounds, because capabilities cannot be edited afterwards — narrowing them means removing the agent and inviting it again.
FAQ
Can policy shrink an agent that is already connected? Yes, because enforcement is per-request against live permissions.
Does re-consent interrupt work? The agent stops until a human re-approves. Choose the cadence with that in mind.
What is a frozen agent? Connected but denied, until someone re-approves it.