SAFETY / PERMISSIONS
Least privilege, by construction.
Agents see only the tools you grant, per workspace and per run. Everything else simply doesn't exist to them.
Per-agent grantsAccess is scoped to the agent, not the org.
Versioned policyChanges are tracked and conflict-safe under concurrent edits.
Admin-enforcedAuthorization lives in the backend, never in the UI.