Spaces and access
An Agent Space is where agents live inside the organization. It defines who does what, and what the agents in that space can reach.
Why a space exists
Without one, "who can publish to production" would be a question for the whole organization. With one, different teams have different spaces, each with its own members, allowed resources, and ceilings.
The roles
Three roles, each containing the previous:
admin ⊃ publisher ⊃ builder
| Action | Builder | Publisher | Admin |
|---|---|---|---|
| Create and edit agents | ✅ | ✅ | ✅ |
| Validate and publish a version | ✅ | ✅ | ✅ |
Activate in development and run there | ✅ | ✅ | ✅ |
Temporary address and schedule in development | ✅ | ✅ | ✅ |
Activate in production, promote, and roll back | ❌ | ✅ | ✅ |
Permanent address and production schedule | ❌ | ✅ | ✅ |
| Re-run a production run | ❌ | ✅ | ✅ |
| Members, allowed resources, and space ceilings | ❌ | ❌ | ✅ |
| The organization's service account | ❌ | ❌ | Organization admin |
There are no "viewer", "operator", or "invoker" roles. The ability to trigger an HTTP address is a credential, not a person's role.
Who joins a space
Access is granted to a person or to a group that already exists in your organization. No new group is created per space or per agent — which avoids the proliferation of groups nobody can review later.
A person has at most one role per space. Changing the role replaces the previous one; there is no accumulation, and therefore no ambiguity about which role applies.
Two layers, both mandatory
1. What the ORGANIZATION permits → Imaginne policies: skills, models, integrations
2. What the SPACE allows → tools, addresses, connections, ceilings
The second is additional, never a substitute. A run has to pass both: allowing a skill in the space does not bypass the organization's policy.
Organization roles as a ceiling
The organization can grant roles that set each person's ceiling in the product — run, build, publish, administer. The effective role in a space is the lower of the person's ceiling and the role granted there.
A ceiling is a limit, never a grant: with no role in the space, there is no access no matter how high the ceiling.
The organization's Imaginne administrator has the admin role in every space — without that, a space whose only admin left the company would be orphaned.
Escalation is blocked
Only admins grant roles, and never above their own level.
Isolation between organizations
A resource belonging to another organization answers as nonexistent, not as "no permission": answering "no permission" would confirm that it exists.
In this section
Tools, skills, connections, and addresses the agents can reach.
Open →Service accountThe identity every agent runs under.
Open →LimitsCeilings on time, iterations, depth, and rate.
Open →Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.