DoReply
Get things done

Govern access and spending

Set roles, agent ceilings, project scope, approvals, and hard budgets that match how the team is accountable.

Govern people and agents as one operating system. Human roles determine what a delegator can reach; agent ceilings and other controls can only narrow that authority.

Quick steps

1. Assign human roles by responsibility

Use Administrator, Manager, Contributor, Viewer, or Billing when a built-in division fits. Create a custom role for a durable responsibility that needs a different mix of view, edit, and manage permissions.

Review or change these assignments from the team's Roles page.

Apply team scope only when the person needs team-wide reach. Prefer project scope for participation limited to a body of work. Review access when a person's job or project changes.

2. Set each agent's ceiling

Choose the maximum permissions the agent's professional role should ever use. Do not raise the ceiling to solve a single poorly scoped card. For every run, effective authority remains the intersection of this ceiling and the delegating person's permissions.

Limit project availability, tool bundles, workspace network access, and destination-bound secrets as additional layers. Confirm that required approvals match the consequence of the actions the agent may propose.

On the agent, review Settings, Model, Tools, Secrets, and Workspaces together. In Workspaces, compare current resources with the team defaults and maximums and review its network policy. In team model settings, confirm which providers and models are permitted before relying on an agent override.

Start with the selected agent's Settings page, then follow its local navigation through the other controls.

3. Set budgets where ownership lives

Open team Billing to review Balance, Reserved (open holds), and Available. Use Add funds or Redeem credit code when authorized. If the team uses Auto-renew, save the intended card, set the minimum and top-up amount, and choose Save. Review the 30-day card charge limit before enabling unattended replenishment.

Set Team budgets for the overall operating boundary and project budgets in the relevant project details for local accountability. Review available funds before starting large parallel work.

Open team Billing for the shared boundary and the selected project's Budgets for local limits.

Budgets are hard limits. When funds or a configured limit prevent execution, work pauses visibly. Investigate the cards, work streams, and expected value before adding capacity; do not increase a limit merely to clear a notification.

4. Review actual usage and exceptions

Inspect cost with the card result and work evidence. Look for repeated retries, unnecessary tool calls, overly broad tasks, or a model whose capability and cost do not fit the job.

Use Funding history to trace additions and download available receipts; use Recent charges, agent Metrics, and agent Logs to connect spend to execution. Review project-level cost on the cards and work streams that produced it.

Review approval decisions and access exceptions in their work context. A pattern of repeated approvals may indicate a legitimate policy adjustment, or it may show that a workflow is operating at the wrong boundary.

5. Revoke and reduce promptly

Remove stale project membership, disable unused tools and automations, revoke unneeded external handoffs, and rotate credentials when ownership changes. Lower an agent ceiling when its role narrows. Reduction should be a normal part of maintenance, not an emergency-only action.

For a periodic governance review, check team and project membership, custom roles, agent ceilings, project availability, model policy, tools, secrets, network rules, automations, external MCP handoffs, budgets, auto-renew, and recent exceptions. Record the owner and follow-up for every retained exception.

What good looks like

Every person and agent has explainable access, consequential requests reach an appropriate reviewer, and spending can be traced to visible outcomes. Paused work identifies the boundary it reached instead of failing silently or continuing beyond it.

Next steps