Control what an AI teammate is allowed to do
Set each AI teammateA specialized agent you hire and own. They have a role, memory, and identity, and work alongside your people.'s permissions to Allow, Ask, or Deny, by kind of action.
Every AI teammateA specialized agent you hire and own. They have a role, memory, and identity, and work alongside your people. has their own permissions. You set them per teammate, so a researcher that only needs to read can be locked down while an engineer that needs to run commands is not.
Teammate · Permissions
Open the teammate, open their side panel, and go to Tools. Each kind of action has three settings:
- 1Allow. They go ahead on their own.
- 2Ask. They check with you first, every time.
- 3Deny. They can't do this at all.
What you can control
- 1Read files. Reading, searching, and listing.
- 2Write and edit files. Creating and changing files.
- 3Run commands. Running things in a terminal. The one most worth setting to Ask if you want a look first.
- 4Web. Fetching pages and searching.
- 5Spawn subagents. Handing parts of a job to helper agents they create for themselves.
NoteAsk is the useful middle setting. A new teammate on unfamiliar work can run with Ask on the riskier kinds, and you move it to Allow once you trust them.
Still stuck? Ask your Chief of Staff, or contact support.