Rovo agent permissions and governance
Manage who can create agents in Studio
Who can do this? Role: Organization admin Atlassian Cloud: Standard, Premium, Enterprise Atlassian Government Cloud: Not available |
Rovo Studio and the ability to create agents is open by default to everyone in your organization. But if you don’t have governance practices in place, this can lead to crowded agent directories.
If needed, organization admins can restrict who creates agents by managing Studio settings.
All users is the default, allowing anyone in your organization to create agents.
Selected groups limits agent creation to up to 10 user groups.
No users limits creation to you and other organization admins.
You can limit agent creation to admins by selecting admin user groups, but any user group can be added.
To manage Studio settings:
Navigate to the Rovo Studio app via the app switcher.
Select Settings from the left-hand navigation.
Select your preferred setting:
All users
Selected groups
No users
To manage Selected groups:
Select Selected groups.
Select Add groups to open a modal.
Use the dropdown to search for and select up to 10 user groups.
Select Add.
Set edit permissions for your agent
If you’re the owner of an agent, you can add individuals as editors or managers to grant them certain permissions.
This allows complex team agents to be managed by multiple people:
Editors can
Edit the agent
Managers can
Edit the agent
Add other editors
Delete the agent
To add editors and managers to an agent:
Select Users and permissions
Select Add user
Search for the user by name, then add them to the agent with desired role.
Control who can see and use your agent
When you create an agent, it becomes available for everyone to see and use by default.
It’s worth noting that from a privacy standpoint, agents can only access information that the person using it has permission to view or edit. But if you’d like to limit access to the agent itself, you can.
Agents with restricted access are only visible by the people you add. Others won't see them in browsing directories or as options for automation.
All agents have a user profile that is visible in your organization’s Atlassian teams directory – but they can’t be opened from this location.
To restrict your agent for your personal use:
Open your agent
Select Users and permissions from the left-hand navigation
Find the User access section
Toggle Open to all users to the Off position
If you have not added users, the agent is now only accessible to you
To limit your agent’s access to specific people:
Select the Add user button to open a modal
Type or select the name of someone
Select a role for them (Editor or Manager)
Select Add
At the moment, you must give users a role when you add them, either editor or manager:
Editors can
Edit the agent
Managers can
Edit the agent
Add other editors
Delete the agent
Restricting agent access to specific groups or teams is currently not supported. You will need to add users individually.
Change an agent’s attribution in the agent directory
When people browse the directory of available agents, each agent is listed by name along with “By <person’s name>”.
An agent is attributed to the person who created it (the owner) by default. But when an agent is managed by a team or you want to highlight its quality by associating a particular team, you can change the attribution to reflect this.
To change the author display name to a specific team:
Open an agent you have edit permissions for
Select Users and permissions from the left-hand navigation
Expand Author display name
Type or select the name of one of your Atlassian teams
What can users access when interacting with an agent?
When someone interacts with an agent, the agent is acting on that person’s behalf. It therefore can only return or interact with spaces, pages, work items, and other information that the user has permission to access. For example:
If the user doesn’t have access to view a page, the agent can’t respond with anything about that page.
If the user can’t comment, the agent can’t comment.
If the user can’t delete a Confluence page, the agent can’t delete the Confluence page.
You can also explicitly limit what an agent can or can’t do in the instructions or by changing what skills it is configured with.
Was this helpful?