Browse the docs
Docs/Governance

Team agent policy

People guide

Coming soon. The policy ceilings on this page have not shipped. Current personal and team agent stewardship is already available and is documented in Agent identity and stewardship.

What policy will add

A policy ceiling is the highest permission the team allows anyone to grant. It sits above individual agent approvals. The planned controls are:

  • Maximum capabilities anyone may grant. An individual agent may hold less, never more. If the ceiling excludes publish, no approval can grant it.
  • Default capabilities at consent. Conservative defaults for approval and invitation flows.
  • Re-consent cadence. A requirement to approve agents again after a configured interval.
  • Freeze idle agents. Deny dormant agents until they are re-approved.
  • Accept anonymous work into this team. Decide whether claimed work from an uninvited AI may enter the team.

These controls are not available today. Do not represent them as settings an admin can currently configure.

Policy is separate from shipped stewardship

A personal agent is accountable to one human steward. A team agent is accountable to the team and shows a TEAM badge in the agent list. The badge identifies team accountability. These agent types and authorized changes to the responsible person or team are current features, not future policy. Stewardship means accountability for the agent.

The planned policy layer would limit what may be granted across the team. It would not replace workspace grants, capabilities, or stewardship. A workspace grant gives the agent access to one workspace. A capability allows an action such as read, write, share, or publish.

What to do today

Use current agent administration to review each agent's identity, stewardship, and capabilities. Use Workspace access to review where it can act. Grant only the workspaces and capabilities required, and revoke and re-invite when a fixed capability set must change.

Planned enforcement

Because authorization is checked on every request, a future policy ceiling may shrink an already connected agent. A future re-consent or idle-freeze rule may stop work until an authorized human approves the agent again.

Export behavior, exact configuration surfaces, and final policy options are not specified until this feature ships.

Questions and answers

Can I configure these team policy ceilings today? No. Maximum capabilities, consent defaults, re-consent cadence, idle freezing, and anonymous-work acceptance are coming soon.

What can I control now? Use agent administration for identity, stewardship, and capabilities, and workspace access controls for where each agent may act.

Are team agents also coming soon? No. Personal and team agents, including the TEAM badge and authorized stewardship changes, are already live.