Skip to main content

Spaces and access

An Agent Space is where agents live inside the organization. It defines who does what, and what the agents in that space can reach.

Why a space exists​

Without one, "who can publish to production" would be a question for the whole organization. With one, different teams have different spaces, each with its own members, allowed resources, and ceilings.

The roles​

Three roles, each containing the previous:

admin ⊃ publisher ⊃ builder
ActionBuilderPublisherAdmin
Create and edit agents✅✅✅
Validate and publish a version✅✅✅
Activate in development and run there✅✅✅
Temporary address and schedule in development✅✅✅
Activate in production, promote, and roll back❌✅✅
Permanent address and production schedule❌✅✅
Re-run a production run❌✅✅
Members, allowed resources, and space ceilings❌❌✅
The organization's service account❌❌Organization admin

There are no "viewer", "operator", or "invoker" roles. The ability to trigger an HTTP address is a credential, not a person's role.

Who joins a space​

Access is granted to a person or to a group that already exists in your organization. No new group is created per space or per agent — which avoids the proliferation of groups nobody can review later.

A person has at most one role per space. Changing the role replaces the previous one; there is no accumulation, and therefore no ambiguity about which role applies.

Two layers, both mandatory​

1. What the ORGANIZATION permits → Imaginne policies: skills, models, integrations
2. What the SPACE allows → tools, addresses, connections, ceilings

The second is additional, never a substitute. A run has to pass both: allowing a skill in the space does not bypass the organization's policy.

Organization roles as a ceiling​

The organization can grant roles that set each person's ceiling in the product — run, build, publish, administer. The effective role in a space is the lower of the person's ceiling and the role granted there.

A ceiling is a limit, never a grant: with no role in the space, there is no access no matter how high the ceiling.

The organization's Imaginne administrator has the admin role in every space — without that, a space whose only admin left the company would be orphaned.

Escalation is blocked​

Only admins grant roles, and never above their own level.

Isolation between organizations​

A resource belonging to another organization answers as nonexistent, not as "no permission": answering "no permission" would confirm that it exists.

In this section​

Next steps​