Skip to content

Organization governance

An organization controls which agents may be installed, which roles may run them, which data sources are available, which models and providers are eligible, and how much spend is allowed.

Installation is not a grant of unrestricted access. The tenant policy is evaluated at runtime. Masking, retention, routing, budget, tool, and side-effect controls remain active for every run.

Organization Admin can suspend an installed version, pin a previous version, revoke a permission, or remove an agent. These actions create audit events and preserve historical run evidence.