Sharing an agent
An agent belongs to one person — the owner, normally whoever created it. Sharing lets other people in your organization use it without handing over control.
Who can do what
| Task | User | Agent owner | Admin |
|---|---|---|---|
| Chat with an agent shared with them | ✅ | ✅ | ✅ |
| Share their own agent with a colleague | — | ✅ | — |
| See who an agent is shared with | — | ✅ | — |
| Change a colleague's Viewer/Editor role | — | ✅ | — |
| Stop sharing | — | ✅ | — |
| Open and configure any agent in the organization | — | — | ✅ |
| Transfer an agent to a new owner | — | ✅ | ✅ |
| Create public share links | — | — | ✅ |
Admins can open and configure every agent in the organization, whether or not it was shared with them. There is no way to hide an agent from an admin.
Every other row here follows the usual rule that an admin can do anything an owner can. Sharing doesn't: managing an agent's shared users is restricted to the person who owns it, even for an admin. An admin who needs to change who can reach an agent transfers it to themselves first — which is a visible act, unlike quietly adding a viewer.
Owner, Editor, Viewer
Access resolves in this order — owner first, then admin, then whatever the agent was shared as:
| Owner | Admin | Editor | Viewer | |
|---|---|---|---|---|
| Chat with the agent, see its history | ✅ | ✅ | ✅ | ✅ |
| Read its files | ✅ | ✅ | ✅ | ✅ |
| Change its name, instructions, and model | ✅ | ✅ | ✅ | — |
| Add and configure tools, bundles, skills | ✅ | ✅ | ✅ | — |
| Write to its workspace files | ✅ | ✅ | ✅ | — |
| See and edit its memories | ✅ | ✅ | ✅ | — |
| Set its bootstrap instructions | ✅ | ✅ | ✅ | — |
| Share it with someone else | ✅ | — | — | — |
| Transfer ownership | ✅ | ✅ | — | — |
| Delete it | ✅ | ✅ | — | — |
The line worth remembering: an Editor can reconfigure the agent but cannot give anyone else access. Sharing stays with the owner. That keeps the list of people who can reach an agent from growing without the owner knowing.
A Viewer sees a read-only banner in the agent view and can still do the thing that matters — talk to it. Note that a Viewer cannot see the agent's memories or its scheduled routines at all; those are configuration, not conversation.
What an agent can't do in a Viewer's session
The restriction isn't only on the interface. When a Viewer is the one chatting, the agent itself loses the tools that would let it reconfigure itself — it cannot change its own settings, manage agents, skills, routines, memory, or identity. Custom tools are withheld too, since their credentials and their descriptions belong to the organization that registered them.
Everything else stays: the agent can still read and write workspace files, run commands, and use its skills. A Viewer can have an agent do real work; they just can't have it change what it is.
This is why an agent may tell a Viewer it can't remember something, while remembering it perfectly well for the owner.
Sharing your agent
You must be the owner.
- Open the agent → Settings → Sharing.
- Pick a User from your organization and a Role — Viewer or Editor.
- Save. They'll find the agent in their own agent list.
To change someone's role or remove them, use the same screen. Removing access is immediate.
If an agent is marked Admin only, the Sharing section doesn't appear — the agent is visible to admins and nobody else, and per-user sharing would contradict that. Turn off Admin only first if you want to share it.
Transferring ownership
Settings → Transfer Ownership moves an agent to a different person in the organization. Both the current owner and an admin may transfer an agent, though in the app the section is shown to admins — an owner who wants to hand their agent on should ask one. Use it when someone leaves, changes role, or inherits a workload.
The new owner gets everything ownership carries, including the right to share. Existing Viewers and Editors keep their access.
Sharing outside your organization
Everything above is for people who have Delegate accounts in your organization. To put an agent in front of someone who doesn't — a customer on your website, a visitor to a help page — use a share link instead:
- Agent → Settings → Share Links (admins only).
- A share link is chat-only, scoped to that one agent, restrictable to named sites, expirable, and revocable at any moment.
- Visitors need no account and get a read-only toolset.
See Embedding an agent in a web page for the full mechanics, and the security model for what a share link deliberately cannot do.
What sharing doesn't change
- Cost. Work a Viewer or Editor asks for is spent by the agent, against the organization's budgets. It doesn't come out of their own allowance — there isn't one.
- Memory. The agent has one memory, shared by everyone who uses it. Anything it learns in one person's session can surface in another's.
- Credentials. Tools configured on the agent run with the agent's stored credentials. Sharing an agent shares the reach of those credentials — check what a shared agent is connected to before you widen access to it.