Access and upkeep

Collaborators

Giving a named person access to one agent, without giving them the rest of the workspace.

A collaborator has access to a single agent. A workspace member has access to every agent the workspace owns. When someone needs one agent and nothing else, use the agent's Collaborators section.

Three ways people reach an agent:

  • Workspace members see every agent, plus numbers, billing and settings.
  • Collaborators reach one named agent, with an account.
  • Share links let anyone with the URL talk to the agent: no account, no access to settings.

Access levels

Two levels, and only two.

LevelCan do
ViewRead settings, calls and results.
EditThe above, plus changing settings.
sam@example.com    View    reads settings, calls and results
dev@agency.com     Edit    also changes settings

What an edit collaborator cannot do

An edit collaborator cannot change:

  • Lifecycle. Archiving, restoring, deleting or deactivating the agent.
  • Public exposure. The agent's share link or slug.
  • Governance. Data retention, PII redaction, telemetry content level and billing exemption.
  • Ownership. Moving the agent to a different workspace (requires membership in both the source and destination workspace).

Edit access cannot be escalated into making the agent publicly reachable, or into weakening what is recorded and kept. The narrowing holds on every route into the agent, not just the UI. See access control for how enforcement is built.

A collaborator also cannot add, remove or change other collaborators, and cannot list who else has access.

Collaborators versus workspace members

CollaboratorWorkspace member
ReachOne agent per grantEvery agent in the workspace
Sees the workspace navNo, only shared agentsYes
Numbers, billing, settingsNoGoverned by their role
Can archive or delete the agentNoYes
Can mint or revoke a share linkNoYes
Can manage collaboratorsNoYes

Where a collaborator lands

A collaborator with exactly one shared agent lands straight on that agent when they sign in. With more than one, they get a list of just those agents.

Inviting someone

Add the person by email address and choose view or edit.

  • If they already have an account, access is live immediately.
  • If they do not, they are emailed a link to claim access. They set a password or sign in, and the grant binds to the account they end up with. Until then the row shows as pending.

Existing members are refused

If the email belongs to an existing workspace member, the invitation is refused. They already have full access, so a per-agent grant would be a confusing downgrade rather than an addition.

Removing access

Remove the person from the list. Access ends at once.

Changing someone between view and edit works the same way and takes effect immediately, with no re-invitation.

On this page