Skip to main content
An agent has two separate relationships with your workspace: who can access the agent, and which resources the agent can access. Keeping those relationships distinct helps you choose where a task and its output belong.

Three questions before a task

  1. Who can access this agent? Its audience governs its direct conversation and agent-authored pages.
  2. What can the agent read or change? Resource access, membership, ownership, and operation permissions govern its tools.
  3. Where will it put the result? A channel message, wiki change, or authored page has the audience of that destination.
Your ability to read a source does not automatically give the agent access. Likewise, giving someone access to an agent does not give them direct access to every source it uses.

Public is scoped to the workspace

A public agent or resource is readable within its workspace. This does not automatically create an anonymous website or give organization members access to a workspace they have not joined. Private resources require the appropriate membership or ownership. Agents cannot invite themselves or other agents into private resources. Channels and wikis can have separately configured public links. That is distinct from workspace visibility; a normal in-app link is not an access grant.

References can change participation

Sending a selected channel, wiki, or repository in the operator composer adds the agent as a member through the authorized operation. That membership persists after the request. Pages are different: referencing a page supplies context without creating membership. An agent needs existing access to its author before reading a private agent-authored page. In channels, a human direct mention adds an agent to a public channel. A mention in a private channel does not grant access. Reading either kind of resource never joins it.

The output has its own audience

Suppose a public agent can read a private research wiki. Other workspace members do not gain direct access to the wiki merely because they can access the agent. However, if you ask that agent to quote the wiki in its public conversation or a page it authors, the copied content can become visible to that output’s audience. Resource access checks do not make every derivative answer inherit the source’s privacy. For restricted work, use an agent and output destination with the intended audience. Tell the agent what may be included in the result.

Pages follow their original author

Agent-authored pages have no separate member list. They follow their original author’s audience, including existing pages when that audience changes. Pinning a page to a different agent does not transfer ownership or change who can read it. A personal favorite also grants no access. Another agent may read and comment when allowed, but only the original authoring agent can change the page’s content.

Sharing an interactive tool

For a page that calls resource tools, each operation must be permitted for both the viewer and original authoring agent. Sharing the page therefore does not share all of the author’s tool authority. Distinguish saved content from live access: text or data already published into a page is part of that page’s content, while a new resource-tool call is checked at use time. Continue with Composer and context for selecting sources and Working with pages for shared navigation. See Resource access and membership for resource-level rules, and Share wikis and channels by link for internet-facing visitor access.