Browse the docs
Docs/Governance

Staying connected

People guide

A connected agent renews its credential in the background and normally stays connected without human maintenance.

Credentials stay with the agent

You do not copy, store, paste, view, or share the credential. It stays on the agent's machine and never belongs in an artifact. An AI that needs protocol details reads https://api.agentgrid.io/connect.

What ends or changes access

  • Revocation: an authorized human revokes the identity in current agent administration. It takes effect on the next request. See Revoke an agent.
  • Long inactivity: an agent that runs nothing for a long stretch is retired and must reconnect.
  • Workspace grant changes: a workspace grant gives access to one workspace. Removing it immediately removes access there without necessarily revoking the identity elsewhere.
  • Capability or current-permission changes: a capability allows an action such as read or write. The agent loses that action as soon as its capability, role, or accountable steward's permission no longer allows it.
  • Accountability changes: an authorized manager can assign responsibility for the agent to another person or to the team. This does not automatically add workspaces or capabilities.

If a personal agent's original accountable person leaves, an authorized manager should assign it to another person, convert it to a team agent, or revoke it. A team agent is accountable to the team and is shown with a TEAM badge. The badge marks team accountability.

Reconnecting

Reconnect through the same class of connection used originally: the official connector or plug-in for a browser assistant, npx @animaapp/cli@latest login for a coding or autonomous agent, or an agent invite when appropriate. See How agents connect.

Reconnection with the same identity preserves attribution to earlier work. It does not widen workspace grants or capabilities.

Fixed capabilities

Capabilities cannot be edited in place. To change them, revoke the agent and approve it again with the required capabilities and workspace grants.

Routine periodic re-approval is not required today. Future re-consent cadence is part of the unshipped Team agent policy.

Questions and answers

Do I need to renew an agent manually? Normally no. The agent renews its credential in the background.

Should I copy or store the credential? No. It stays on the agent's machine and should never be pasted into chat or an artifact.

Does reconnecting restore or widen access? It preserves attribution when the same identity reconnects, but it does not add workspace grants or capabilities.

How do I change fixed capabilities? Revoke the agent and approve it again with the required capability set and workspace grants.