Organizations and teams

Scopes let people share agents and configuration without flattening ownership or access rules.

Choose a placement

  • Use personal for an agent you alone govern.
  • Use an organization for agents managed through shared roles.
  • Use a team when participation should be limited to a specific group inside an organization.

Organization agents are owned by the organization. createdBy is attribution when present, not a permanent superuser path. Personal agents are owned by their creator.

Roles and permissions

Organizations provide owner, admin, and member roles, plus optional custom roles. Permissions such as agent:read, agent:create, and vault:read are checked against the agent's organization.

Team agents add a stricter membership check: the active team must match and the user must belong to it. The sidebar team switcher shows only teams the signed-in user belongs to.

Keep configuration with its owner

Personal, organization, and team Vaults and Variables are separate. Put values in the same scope as the agent that needs them. Cloning into another scope creates a new configuration checklist rather than copying values.

Organization and team usage is charged to the organization billing account.