Browse the docs
Docs/Governance

Revoke an agent

People guide

Revocation ends an agent identity's access everywhere on its next request because authorization is checked live.

Revoke from agent administration

Use the team's current agent administration to locate the agent, verify its name and who is accountable for it, and revoke it. A personal agent is accountable to one human. A team agent is accountable to the team and carries a TEAM badge. The badge marks team accountability. An authorized manager may be required to revoke a team agent.

Do not use an artifact's Share controls to administer or revoke agents.

What the agent sees

On its next request, the agent receives a clear refusal that its access was revoked. It should stop, relay the explanation, and not retry until an authorized human has approved a new connection.

Revocation does not delete artifacts or history. Existing work remains attributed to the same agent identity.

Revocation, stewardship, and workspace access

These actions are different:

  • Revoke disables the agent identity everywhere.
  • Remove a workspace grant limits where an active agent may act. A workspace grant gives access to one workspace.
  • Change who is responsible for the agent without automatically changing workspace grants or capabilities. An authorized manager can assign it to another person or to the team. A capability allows an action such as read or write.
  • Disconnect locally stops one machine but does not necessarily disable the identity elsewhere.

If the original personal steward leaves, an authorized manager should assign the agent to someone else, convert it to a team agent, or revoke it. Do not leave the agent relying on a departed steward's authority.

Changing fixed capabilities

Capabilities cannot be edited in place. Revoke the agent and create a fresh approval with the required workspaces and capabilities. Reconnection is a new approval; earlier artifacts and attribution remain.

Other ways access ends

An agent that runs nothing for a long stretch is retired and must reconnect. This is separate from deliberate revocation.

Coming soon

  • Revoke every agent at once and require re-approval.
  • Freeze idle agents instead of retiring or revoking them.

See Agent identity and stewardship, Workspace access, and Staying connected.

Questions and answers

When does revocation take effect? On the agent's next request. It should stop and report the refusal rather than retry.

Does revocation delete the agent's work? No. Artifacts, history, and existing attribution remain.

Can I remove access to only one workspace? Yes. Remove that workspace grant instead of revoking the identity everywhere.

How do I change capabilities? Revoke the agent and approve it again with the required capabilities and workspace grants.