Skip to main content
Some agents open only for the people named on them. As a workspace admin you still oversee them: you see every one, what it can reach and what it costs, and you can stop it. What you don’t see by default is what it works with. This page answers the questions admins usually ask about that. There are three kinds of agent: For everyone else, restricted and personal agents look the same: only the people named on them know they exist. They differ in who oversees them and what governs them. See Restricted agents and Personal agents.

What can’t I see, and why is that a good thing?

You don’t see an agent’s inside: its instructions, documents, chats, diary, activity log, and individual key metric records. That’s what the agent works with, and it often holds what people would only share with the agent—an HR case, their own mailbox, a draft they’re not ready to show. If admins could read all of it, people would keep that work off the platform, where nobody oversees it at all. Instructions count as inside because an agent is steered as much by its documents as by its instructions: showing one without the other would give you a misleading picture.

What can I always see, about every agent in my workspace?

Its shell: what its owners wrote about it and what it costs. On the Agent Management page you see, for every agent:
  • Its name, description, owners, and everyone else with access and at what level
  • Its value statement, criticality, and key metric definitions and totals
  • Which capabilities, integrations, Outgoing APIs and MCP servers it has, and how it’s exposed (widget, HTTP API, MCP server, webhooks)
  • Its model, lifecycle phase, tags, and credit usage
Team admins see the agents in their teams on the same page, but not personal agents, which belong to no team.

What can I do about an agent I can’t open?

You can:
  • Disable or enable it
  • Delete it
  • Limit its daily credits
  • Change its model or lifecycle phase
On a restricted agent you can also move it, change its tags, and choose who has access, yourself included. You can’t trigger an agent you’re not named on: a message from you could ask it to send you its documents.

Can someone hide an agent from me completely?

No. Every agent in the workspace is listed on the Agent Management page for workspace admins, restricted and personal ones included, and its credit usage shows on the Usage page. Nobody can turn that off.

Can an agent reach data or systems I haven’t approved?

No more than any other agent. A restricted agent follows its team’s capability settings, and a personal agent the rules you set for personal agents. Beyond that:
  • Secrets and Outgoing APIs reach only the agents they’re shared with: the entire workspace, certain teams or certain agents. Personal agents belong to no team, so a team-wide share doesn’t reach them. See Outgoing APIs.
  • MCP servers can be disallowed for the workspace, a team, or personal agents with the Allow MCP Servers capability setting.
  • Personal tokens connect a person’s own accounts, such as their mailbox. An agent can only use the tokens of the people who connected them to it.

Can personal agents run up costs?

Not beyond what you allow. Under Workspace → Settings → Personal agents you set a monthly credit limit per person, shared by all of that person’s personal agents. Each agent also has a daily limit, the workspace default unless you set another. The people using a personal agent see the monthly limit in the agent’s settings and get a warning in chat as it runs low. See Usage & Limits.

How do I look inside a restricted agent when I need to, and who will know?

Give yourself access. On the Agent Management page, expand the agent’s row, click Add under People with access, pick yourself and an access level—Use to look, Edit or Owner to change it. You can then open it like any other agent you have access to. You can give other people access the same way. The change is recorded in the agent’s activity log, which its owners see, and in the workspace’s User action log, as for example “Gave themselves Owner access”. Owners aren’t notified in any other way. Remove yourself again when you’re done.

How do I look inside a personal agent?

You can’t add yourself to someone’s personal agent. Ask its owner to add you by name, or, if that isn’t possible, contact support@abundly.ai.

What happens when the owner leaves?

A restricted agent keeps running, and nobody can open it until an admin adds a new owner on the Agent Management page. Give restricted agents a second owner to avoid the gap. A personal agent keeps running until you disable or delete it, and only the people its owner named can still open it. If someone should take it over, ask the owner to move it into a team before they leave.

Can I switch personal agents off, or limit what they can do?

Yes:
  • Workspace → Settings → Personal agents turns them on or off. When off, nobody can create new ones; existing ones keep working until their owners move them into a team or you delete them.
  • Capabilities → Personal agents decides what they may use, like a team’s capability settings: switch capabilities off, choose which ones new personal agents start with, lock settings such as requiring approval for outgoing email, and add extra instructions.

Restricted or personal: which should people use for what?

  • A personal assistant connected to someone’s own mailbox or calendar: a personal agent. It works for one person, so it shouldn’t sit in a shared team.
  • Sensitive data, such as HR cases: a restricted agent in the team that owns the work. It follows the team’s capabilities, Outgoing APIs and secrets, and an admin can step in when needed.
  • Just trying something out: a personal agent. If it turns out useful for others, its owner moves it into a team.

Learn more

Access Control

Roles, access levels and restricted agents

Teams

Teams and personal agents

Agent Management

Oversee every agent in one place