Agents
How-to

Share access to an Agent

Grant direct or Organization-wide Agent Access Roles, understand additive Permissions, and safely change or remove access.

For
Agent owners, access managers, Organization administrators, and security reviewers
On this page
  1. Overview
  2. Agent access model
  3. Compare Agent Access Roles
  4. Before you begin
  5. 1. Open Share
  6. 2. Review available roles
  7. 3. Grant direct access
  8. 4. Configure General access
  9. 5. Change or remove access
  10. 6. Save and verify
  11. How additive Permissions work
  12. Special access cases
  13. Sharing API
  14. Security checklist
  15. Troubleshooting
  16. Next steps

Sharing controls which Organization Members can find, inspect, operate, configure, or administer an Agent inside Agent Barn.

Agent Barn supports direct access for selected Members, and Agent General Access for all accepted Organization Members. These grants are additive: a Member receives the combined Permissions available from every applicable access source.

Overview

An Agent remains owned by its Organization. Sharing grants authority over that Agent; it does not transfer ownership of the underlying resource.

Access source Audience Scope
Direct Agent AccessOne accepted Organization MemberOne Agent Access Role on one Agent
Agent General AccessAll current and future accepted Organization MembersOne Agent Access Role on one Agent
Implicit Organization authorityOrganization Owner and Organization AdminFull authority over every Agent in the Organization

New Agents use Restricted General access by default. Their creator receives a direct Agent Owner assignment when the Agent is created.

Organization Owners and Organization Admins always have full authority over Agents in their Organization. They are not listed as direct assignments in the Share dialog.

Agent access model

Agent Barn calculates effective authority from all applicable sources.

  • Implicit Organization authority
  • Direct Agent Access
  • Agent General Access
  • Effective Agent Permissions

Permissions are allow-only. One access source cannot reduce Permissions granted by another.

For an ordinary Organization Member:

  • No direct grant and Restricted General access means no Agent access.
  • A direct grant gives the Member its selected Agent Access Role.
  • General access gives the Member its configured role automatically.
  • When both apply, the Member receives the union of both Permission sets.

Agent Access covers the complete Agent aggregate, including:

  • Agent metadata
  • Configuration
  • Lifecycle operations
  • Conversations
  • Tool Calls
  • Activity
  • Logs
  • Agent-specific costs
  • Skills
  • Credential metadata and management, when permitted
  • Access management, when permitted

Secret plaintext is never returned through read access.

Compare Agent Access Roles

Every Organization includes three locked Agent Access Roles.

Role Capabilities
Agent ViewerView the Agent, Conversations, Tool Calls, activity, Logs, and Agent-specific costs
Agent EditorViewer capabilities, plus configuration, lifecycle, Skill assignment, and Agent Secret management
Agent OwnerEditor capabilities, plus Agent retirement and access management

The Permission progression is cumulative.

  1. Agent Viewer Read the Agent, its activity, and its costs
  2. Agent Editor Viewer authority, plus configuration, lifecycle, Skills, and Agent Secrets
  3. Agent Owner Editor authority, plus retirement and access management

Agent Viewer

Use Agent Viewer for people who need to:

  • Inspect the Agent
  • Review Conversations and Tool Calls
  • Review health and Logs
  • Review Agent-specific costs
  • Diagnose behavior without changing it

Agent Viewer is the recommended starting role when someone needs visibility but not operational control.

Agent Editor

Use Agent Editor for people who need to:

  • Configure the Agent
  • Start and Pause the Agent
  • Assign or repin Skills
  • Manage platform and integration credentials
  • Apply configuration changes that restart the Runtime

Agent Editor includes sensitive operational authority. An Editor can alter how the Agent behaves, and which credentials it uses.

Agent Owner

Use Agent Owner only for trusted administrators who need to:

  • Perform every Editor operation
  • Retire the Agent
  • Open Share
  • Grant, change, or remove other Members’ access
  • Configure Agent General Access
  • Grant Agent Owner to other Members

An Organization may also define custom Agent Access Roles. When custom roles are available, review their actual Permission summary rather than inferring authority from the role name.

Before you begin

You need:

  • Access to the Organization that owns the Agent
  • Access to the Agent
  • The agent.access.manage Permission
  • The recipient already added to the same Organization
  • The recipient’s invitation accepted
  • A clear reason for the requested level of access
  • A decision between direct access and Agent General Access
  • A plan for verifying the recipient’s effective authority

The locked Agent Owner role includes agent.access.manage. Organization Owners and Organization Admins also have implicit authority to manage Agent access.

If the Share action is missing, your effective Permissions do not include access management.

Open Share

  1. Select the Organization that owns the Agent.
  2. Open the Agent from Home.
  3. Select Share in the Agent header.
[Agent name] Runtime · platform · condition
Configuration Share

The Share dialog is titled:

Share dialog
Share [Agent name]

Manage who can access this Agent,
directly or through General access.

The dialog contains:

  • A Member search
  • A role-help action
  • People with access
  • General access
  • Cancel
  • Save

Changes remain local to the dialog until you select Save.

Organization Owners and Organization Admins are not included under People with access, because their full access is implicit and cannot be revoked through Agent sharing.

Review available roles

Select the help icon in the Share dialog to open Agent Access Roles.

? Agent Access Roles
Viewer — View, See activity, See costs

Editor — View, Edit, Start/stop, Manage secrets,
         See activity, See costs

Owner  — View, Edit, Start/stop, Manage secrets,
         Delete, Manage access, See activity, See costs

The role legend lists the Permissions currently attached to each available role. Roles containing sensitive Permissions display an additional warning. In particular, look for roles that can:

  • Delete the Agent
  • Manage who has access to the Agent

Use the least-privileged role that supports the recipient’s responsibilities.

Responsibility Recommended locked role
Observe and diagnoseAgent Viewer
Configure and operateAgent Editor
Retire and manage accessAgent Owner

Custom roles may not follow this exact hierarchy. Read their Permission summary before selecting them.

Grant direct access

Direct access grants one Agent Access Role to one accepted Organization Member for this Agent.

Find the Member

In the Share dialog:

  1. Search by the Member’s name or email address.
  2. Find the intended Member in the results.
  3. Review their email carefully.
  4. Select the Agent Access Role.
  5. Select Add.
Agent Operator [email protected]
Viewer Add

The Member appears under People with access, but the grant is not active until you select Save.

A search result may show one of these conditions:

Condition Meaning
Role selector and AddThe Member can receive direct access
Already has accessThe Member is already in the local assignment list
Owner — full access alreadyThe Organization Owner already has implicit full authority
Admin — full access alreadyThe Organization Admin already has implicit full authority
Pending inviteThe invitation must be accepted first

Only accepted Members of the same Organization are eligible. Users from another Organization cannot be granted access to this Agent.

Direct-assignment rules

  • One Member can have at most one direct Agent Access Role for an Agent.
  • The same Member can have different roles on different Agents.
  • Direct access applies only to the selected Agent.
  • Changing an Organization Role does not automatically create a direct Agent assignment.
  • Removing the Member’s Organization Membership removes their direct Agent Access.

Configure General access

Agent General Access defines whether accepted Organization Members automatically receive access to this Agent. Choose one of two modes.

Restricted

No Organization-wide Agent Access Role is granted. Access is limited to:

  • Directly assigned Members
  • Organization Owners
  • Organization Admins

Restricted is the default for new Agents. It does not remove direct assignments, and it does not affect the implicit authority of the Organization Owner or Organization Admin.

All Organization Members

Every current and future accepted Organization Member receives the selected Agent Access Role. The grant applies dynamically to:

  • Current accepted Organization Members
  • Members who accept an invitation later
  • Future Members added to the Organization

It does not apply to pending invitees, removed Members, or users outside the Organization.

The selected role must include permission to read the Agent.

Choose a safe General Access role

General Access role Effect
Agent ViewerEvery accepted Member can find and inspect the Agent
Agent EditorEvery accepted Member can configure, start, Pause, and manage credentials for the Agent
Agent OwnerEvery accepted Member can retire the Agent and manage its sharing

Changing the General Access role affects the next request made by each applicable Member. It does not create a separate direct assignment for every Member.

Change or remove access

Existing direct assignments appear under People with access.

Agent Operator (creator) [email protected]
Editor Remove access

Change a direct role

  1. Find the Member.
  2. Open their role selector.
  3. Select the new Agent Access Role.
  4. Review other pending changes.
  5. Select Save.

A role change replaces that Member’s direct role for this Agent.

If Agent General Access also applies, the Member continues to receive the union of the direct and General Access Permissions.

Remove direct access

  1. Find the Member.
  2. Open their role selector.
  3. Select Remove access.
  4. Select Save.

If General access is All Organization Members, removing a direct assignment does not remove all of the Member’s access. The interface warns that the Member still has the General Access role.

Remove General access

Set General access to Restricted, then select Save.

This removes the Organization-wide grant but preserves every direct assignment.

Change the General Access role

Keep All Organization Members selected and choose a different role.

The new General Access role applies to current and future accepted Members after the change is saved.

Removing your own access

A user with agent.access.manage may be able to remove or reduce the direct grant that currently authorizes them.

Review your remaining General Access or Organization authority first. After the save, you may lose the ability to reopen the Agent or correct its sharing settings.

Organization Owners and Organization Admins retain implicit recovery authority.

Save and verify

The Share dialog saves the complete desired sharing state.

  1. Local sharing draft Additions, role changes, and removals stay in the dialog
  2. Save The dialog sends General access and the complete direct-assignment list
  3. One atomic access snapshot Every change applies together, or none of them applies

Selecting Save sends:

  • The selected General Access role, or Restricted
  • The complete list of direct Member assignments
  • The selected Agent Access Role for each assignment

The update is atomic. If saving fails, none of the sharing changes are applied, and the local draft remains available in the dialog.

After a successful save, Agent Barn displays Sharing updated.

Verify direct access

Ask the recipient to:

  1. Refresh Agent Barn.
  2. Select the correct Organization.
  3. Confirm that the Agent appears on Home.
  4. Open the Agent.
  5. Confirm that controls match the intended role.
Role Expected controls
Agent ViewerRead-only Agent and activity views
Agent EditorConfiguration and lifecycle controls, without Share or retirement
Agent OwnerConfiguration, lifecycle, Share, and retirement controls

Verify Restricted access

Use an accepted Organization Member who has no direct assignment, and no Organization Owner or Admin authority. They should not be able to find or open the Agent.

Inaccessible Agents are concealed as not found, rather than revealing that the resource exists.

Verify General access

Use an accepted Organization Member without a direct assignment. They should be able to find the Agent and receive the controls associated with the selected General Access role.

How additive Permissions work

Direct Agent Access and Agent General Access are both positive grants.

General access Direct access Effective result
RestrictedAgent ViewerViewer Permissions
Agent ViewerNoneViewer Permissions
Agent ViewerAgent EditorCombined Permissions equivalent to Editor
Agent EditorAgent ViewerEditor Permissions remain; Viewer does not reduce them
Agent ViewerAgent OwnerOwner Permissions
Agent EditorDirect assignment removedEditor Permissions remain through General access
RestrictedDirect assignment removedNo access for an ordinary Organization Member

With custom roles, the combined Permission set may not correspond to one named role. For example:

Combined Permissions
Custom direct role:
- View
- See activity
- Manage access

General Access role:
- View
- Edit

Effective Permissions:
- View
- See activity
- Manage access
- Edit

Neither role overrides the other.

To reduce effective authority, remove or change every source granting the unwanted Permission.

Special access cases

Organization Owner and Organization Admin

Organization Owners and Organization Admins have implicit Agent Owner authority over every Agent in their Organization. They:

  • Are not listed under People with access
  • Cannot be granted a redundant direct assignment through Share
  • Cannot have their Agent authority revoked through Share
  • Can recover access settings when another access manager loses authority

Their Organization Role must be changed through Organization membership administration, not Agent sharing.

Agent Creator

Agent Creator records who originally created the Agent. Creation normally grants that person direct Agent Owner access, and the Share dialog labels the assignment with (creator).

Creator identity is immutable provenance, but it is not a permanent authorization source. If the creator’s direct access is changed or removed, the creator label does not independently restore authority.

The creator may still have access through:

  • Agent General Access
  • A later direct assignment
  • Organization Owner or Admin authority

Pending invitees

Pending invitees cannot receive direct Agent Access. They also do not receive Agent General Access until they accept the invitation and become an accepted Organization Member.

If General access is enabled, the role applies automatically after acceptance.

Removed Members

Removing a Membership removes that person’s direct Agent Access.

Removed Members also stop receiving Agent General Access, because they are no longer accepted Members of the Organization.

Custom Agent Access Roles

An Organization may provide custom Agent Access Roles. Custom roles:

  • Use the same Agent Permission catalogue
  • May grant a nonstandard combination of capabilities
  • May not follow the Viewer, Editor, Owner hierarchy
  • Take effect according to their current Permission definition
  • Must belong to the same Organization when Organization-scoped

Review the role help before assigning one. For General access, the role must include agent.read.

Sharing API

The sharing endpoints operate inside the active Organization context.

Method and endpoint Purpose Required authority
GET /agents/share-rolesList Agent Access Roles available to the OrganizationActive Organization Membership
GET /agents/{agent_id}/shareRead the Agent’s General access and direct assignmentsagent.access.manage
PUT /agents/{agent_id}/shareAtomically replace the complete sharing snapshotagent.access.manage
GET /organizations/{organization_id}/members?search=...Search Organization Members for direct assignmentApplicable Organization and Agent authority

Read the sharing snapshot

A sharing response contains General access and direct assignments:

Sharing snapshot
{
  "general_access": {
    "role": null
  },
  "assignments": [
    {
      "user_id": "00000000-0000-0000-0000-000000000001",
      "email": "[email protected]",
      "full_name": "Agent Operator",
      "organization_role": "MEMBER",
      "is_pending": false,
      "is_creator": false,
      "access_role": {
        "id": "00000000-0000-0000-0000-000000000002",
        "name": "EDITOR",
        "permissions": [
          "activity.read",
          "agent.lifecycle.manage",
          "agent.read",
          "agent.secret.manage",
          "agent.update",
          "cost.read"
        ],
        "is_locked": true
      }
    }
  ]
}

A null General access role means Restricted.

Replace the complete snapshot

To keep General access Restricted and grant one direct role:

Restricted General access
{
  "general_access_role_id": null,
  "assignments": [
    {
      "user_id": "00000000-0000-0000-0000-000000000001",
      "access_role_id": "00000000-0000-0000-0000-000000000002"
    }
  ]
}

To enable General access, provide its role ID:

Organization-wide General access
{
  "general_access_role_id": "00000000-0000-0000-0000-000000000003",
  "assignments": [
    {
      "user_id": "00000000-0000-0000-0000-000000000001",
      "access_role_id": "00000000-0000-0000-0000-000000000002"
    }
  ]
}

Each user may appear only once in the assignment list. Every assignment must reference an accepted ordinary Member of the same Organization, and an Agent Access Role available to that Organization.

Security checklist

Before saving:

  • Verify the recipient’s email address
  • Confirm that the recipient belongs to the correct Organization
  • Choose the least-privileged role
  • Review whether General access also applies
  • Avoid broad Agent Editor access unless every Member should manage configuration and credentials
  • Avoid broad Agent Owner access unless every Member should retire and reshare the Agent
  • Check whether the change removes your own recovery path
  • Remove temporary access after the work is complete
  • Review custom-role Permissions rather than trusting the name
  • Confirm the result using a non-administrative test Member

Troubleshooting

The Share action is missing

Your effective Permissions do not include agent.access.manage.

Agent Owner includes this Permission. Organization Owners and Organization Admins also have implicit full authority. Ask an existing access manager to review your role.

Confirm that:

  • The user has been invited to the same Organization
  • You are working in the correct active Organization
  • The name or email search is correct
  • The Organization Membership has not been removed
  • The search is specific enough

The dialog displays the first matching results. Refine broad searches to find additional Members.

The Member appears as Pending invite

The user must accept the Organization invitation before receiving direct Agent Access. After acceptance, search again and add them.

If General access is enabled, it begins applying automatically after their Membership is accepted.

The Organization Owner or Admin cannot be added

This is expected. Organization Owners and Organization Admins already have implicit full authority over every Agent in the Organization.

They are not represented as revocable direct assignments.

Removing direct access did not remove the Agent

The Member may still have access through Agent General Access.

Review General access and the selected role. Direct and General Access Permissions are additive. The Member may also be an Organization Owner or Organization Admin.

Selecting a lower direct role did not reduce access

A lower direct role cannot subtract Permissions granted through General access. For example, direct Agent Viewer does not reduce General Agent Editor authority.

Change or remove the broader General access grant if the Member should lose those Permissions.

A Member still sees controls from their previous role

Access changes take effect on the next request.

Ask the Member to refresh the Agent page and confirm that they are using the correct active Organization. If the controls remain, review every applicable access source.

Saving reports that the Member is unavailable

The Membership may have changed after the Share dialog was opened. The Member may have:

  • Been removed
  • Changed to Organization Owner or Admin
  • Become unavailable in the active Organization

Reload the Share dialog and review the current Organization Membership.

Saving reports that the role is unavailable

The selected custom role may have been changed or removed after the dialog opened, or it may belong to another Organization.

Reload the role list and choose an available role.

General access role is rejected

The selected role must include agent.read.

Choose a role that permits Members to open the Agent.

Saving fails after several edits

The sharing update is atomic. A failure means none of the draft changes were applied.

Keep the dialog open, correct the reported problem, and save again. If the underlying Membership or role changed, reload the sharing settings before retrying.

You removed your own access

If General access still applies, you retain the Permissions from that role.

Otherwise, ask an Organization Owner, Organization Admin, or another Agent access manager to restore a direct assignment.

Next steps

After sharing the Agent:

Documentation