Allow-list which tools are available within a workspace.
Workspace groups are allow-lists. If your organization wants to restrict which tools agents can use — say, only internal tools in production or only approved providers for a compliance-sensitive workspace — you define it here. By default everything is available; once you create a group, only the tools in that group remain accessible.Workspace tool groups are allow-lists that control which tools can be used in a workspace. They let platform operators constrain the catalog to an approved set, independent of per-agent bindings.
Creating a group without understanding the effect. The first group switches the workspace from “all allowed” to “only listed.” Review the list before adding one.
Forgetting to update the allow-list. New tools agents need will not work until added to an active group.