Skip to main content
Workspace groups are allow-lists. If your organization wants to restrict which tools agents can use — say, only internal tools in production or only approved providers for a compliance-sensitive workspace — you define it here. By default everything is available; once you create a group, only the tools in that group remain accessible. Workspace tool groups are allow-lists that control which tools can be used in a workspace. They let platform operators constrain the catalog to an approved set, independent of per-agent bindings.

Key concepts

How it works

Once you define a group, the workspace is restricted to the tools it lists. This is an explicit allow-list; tools not in any group become unavailable.

Getting started

Errors

Security

Adding a workspace group to a previously open workspace immediately restricts all agents in it. Verify the allow-list before creating the first group.

Common mistakes

  • Creating a group without understanding the effect. The first group switches the workspace from “all allowed” to “only listed.” Review the list before adding one.
  • Forgetting to update the allow-list. New tools agents need will not work until added to an active group.

Best practices

  • Decide deliberately whether a workspace should be open or allow-listed.
  • Keep allow-lists current as teams adopt new tools.
  • Use groups to enforce organizational tool policy centrally.

Bindings

Per-agent access within the allow-list.

Tool Catalog

The tools you can allow.

Members & Roles

Who can manage groups.

Tool Gateway

The full model.