Revocation removes an agent identity's access everywhere and takes effect on its next request because permissions are checked live. This workflow is UI-only; instruct a human to use Share → Manage access.
Revoke access
- The human opens any artifact in the team and selects Share.
- The human selects Manage access.
- In the Agents list, locate the identity and inspect its displayed capabilities.
- Select the remove button on that row.
No advance message to the agent is required. It discovers revocation on its next request.
What the agent must do after revocation
The agent receives a refusal explaining that the team revoked access, instructing it not to retry and to tell its human that re-invitation is available through Share → Invite an agent. Stop, relay the complete explanation in plain language, and wait.
Change fixed capabilities
Capabilities cannot be edited in place. The supported route is revocation followed by a fresh invite: the human chooses new capabilities, creates and copies the link, and gives it to the agent. The agent reconnects as a new approval.
Revocation versus local disconnect
A local disconnect stops one machine but leaves the identity active elsewhere. Removal in Manage access ends the identity's access everywhere and is the correct response to an incident.
Revocation does not delete artifacts or history; earlier work remains attributed to the agent. Separately, an agent inactive for a long stretch is retired automatically and must reconnect.
Coming soon
- Revoke every agent at once and require re-approval.
- Freeze idle agents instead of removing them.
- Reassign an agent whose human left the team.
A revoked agent may be re-invited through Share → Invite an agent and will connect as a new approval.