Security

Operate

Security

Control who can configure, invoke, and observe agentic work.

Boundaries

  • Organization membership and roles scope access to workspace resources.
  • Agent and fleet deployment state controls external invocation.
  • Integration keys are scoped to the intended resource.
  • Connector and tool assignments limit what an agent can call.
  • Run traces provide an audit trail of retrieval, actions, and decisions.

Secrets

Provider keys and connector credentials are write-only after saving. Keep separate credentials by environment, rotate them regularly, and revoke them immediately when ownership or scope changes.

High-impact actions