Agent administration
Administer Lifecycle Agent availability, models, instructions, permissions, tools, workspaces, and session audit.
Agent administration controls Lifecycle Agent and Agent Sessions. Restrictive global settings provide the starting policy. Repository settings can supply necessary differences.
Agent administration is available only to Lifecycle administrators. If the section is missing, ask the deployment owner if Agent Sessions is available.
Find the right section
| Section | Use it to |
|---|---|
| Availability & models | Configure Agent availability, providers, allowed models, and defaults |
| Instructions & run limits | Set administrator guidance and bound agent iterations |
| Permissions & approvals | Allow, require approval for, or deny action categories |
| Tools & integrations | Control built-in tools and shared MCP servers |
| Agent workspaces | Configure workspace behavior and cleanup |
| Runtime backends | Configure workspace provider connections, tests, and activation |
| Safety lists | Exclude tools or paths and constrain file writes |
| Session review | Examine session, run, tool, approval, and usage history |
Personal settings are in different sections:
- Use My connections for your provider keys and tool sign-ins.
- When policy permits custom Agent definitions, use My agents to manage them.
Make a safe change
- Select the intended scope: Global or one repository.
- Record the current behavior.
- Change one policy subject.
- Use prompt preview or the section’s test action.
- Save the change.
- Start a new session as a representative non-admin user.
- Do an allowed action, an approval-required action, and a denied action.
- Before you expand the change, examine the session record.
Repository settings combine with global settings. Examine the combined result because a repository setting can make the policy less restrictive.
Use least privilege
- Offer only models approved for the data users will send.
- Allow read-only tools first.
- Require approval for workspace writes, shell commands, Git changes, network access, Kubernetes mutations, and external writes.
- Only if an approved workflow makes it necessary, apply a less restrictive policy.
- Deny capabilities that are not necessary for the workflow.
- Constrain repository and file writes.
- Limit custom Agent creation until an owner and an approval procedure are available.
- After you change a shared MCP server, examine the tools in a test session.
Agent instructions are guidance, not a security boundary. Enforce security with authenticated routes, tool capability policy, approval policy, workspace isolation, repository constraints, and provider controls.
Examine sessions
Use Session review to find:
- the user who started the session
- the target repository, Environment, or workspace
- the selected model and Agent definition
- tool results and approval results
- the current workspace status
Tool input and output can contain sensitive data. Give access to Session review only to administrators with a support or security task. Follow your organization’s retention policy.
Related configuration
- Configure Lifecycle Agent covers instructions, overrides, and approval semantics.
- MCP integration covers shared servers and personal connections.
- Workspace backends covers provider activation and tests.
- Agent Sessions shows the user workflow that you must test.
Roll back
If a change behaves unexpectedly, complete these steps:
- Disable the affected capability or restore the prior policy.
- Examine active sessions that can still use the previous settings.
- Start a new session to make sure that the rollback works.
- Keep related request IDs and session information for investigation.