# Gumloop 官方文档 — Agent Access（Owner / User 双角色 + 8 项 User Permissions）

> 来源：https://docs.gumloop.com/core-concepts/agent_access.md
> 抓取日期：2026-09-20（v10.30.0 Kyuquot / v11.0.0 Conche）
> 关联：v11.0.0 Agent Owners and Users（9/13 ✅ SPEC 候选 → spec_agent-owner-user-roles.md）

---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gumloop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Access

Agents have exactly **two roles**: **Owners** manage the agent, **Users** run it. Everything on this page is configured from the **Access** tab of the agent.

## Owner vs. User at a glance

|                                                                                 | Owner |               User              |
| ------------------------------------------------------------------------------- | :---: | :-----------------------------: |
| Run the agent and start tasks                                                   |   ✅   |                ✅                |
| See instructions, model, connectors, skills, knowledge, subagents, secret names |   ✅   | Only what Owners choose to show |
| Edit any of the above                                                           |   ✅   |                ❌                |
| Create their own triggers                                                       |   ✅   |     Only if Owners allow it     |
| Manage every trigger on the agent, including other people's                     |   ✅   |                ❌                |
| Add/remove Owners and Users, change General Access                              |   ✅   |                ❌                |
| Set User Permissions and Task Visibility                                        |   ✅   |                ❌                |
| See every task on the agent                                                     |   ✅   |    Depends on Task Visibility   |
| Delete the agent                                                                |   ✅   |                ❌                |

<Tip>
  As an **Owner** you tune exactly what Users can see and what they can create on the agent — and you can add as many Owners as you like to share that control.
</Tip>

<Frame>
  <img src="https://mintcdn.com/agenthub/84fGXNKesLzBkaKi/images/agents/access_tab.png?fit=max&auto=format&n=84fGXNKesLzBkaKi&q=85&s=725cc44ae2b99731c32402dd08b1f568" alt="Access tab showing Owners, Users, General Access, File Sharing, Task Visibility, and User Permissions" width="420" data-path="images/agents/access_tab.png" />
</Frame>

***

## Give someone access

Everyone below is added from the **Share** button at the top of the agent, which opens the **Share This Agent** modal. The same controls also live in the **Access** tab of the agent configuration.

<Tabs>
  <Tab title="Add one person">
    **Share** → type their email in **Add people** → pick the role next to the **Share** button → **Share**.

    * *Can manage this agent* = Owner
    * *Can use this agent* = User

    A direct email grant sticks: it keeps working even if General Access is lowered later.
  </Tab>

  <Tab title="Open it to a group">
    Instead of adding people one by one, set **General Access** in the Share modal. Everyone who comes in this way is a **User** — there is no role picker.

    <Frame>
      <img src="https://mintcdn.com/agenthub/V62OUo6iBAfBS2AS/images/agents/share_agent_modal.png?fit=max&auto=format&n=V62OUo6iBAfBS2AS&q=85&s=b041bb0fc75d8e49ea847be2b3bc131f" alt="Share This Agent modal with the General Access dropdown open, showing Restricted, Organization, and Anyone" width="480" data-path="images/agents/share_agent_modal.png" />
    </Frame>

    | Setting          | Who can use the agent                                             |
    | ---------------- | ----------------------------------------------------------------- |
    | **Restricted**   | Only Owners and people added by email (personal agents only).     |
    | **Team**         | Everyone in the team the agent lives in.                          |
    | **Organization** | Everyone in your organization.                                    |
    | **Anyone**       | Anyone with the link, including people without a Gumloop account. |

    <Info>Agents that live in a team cannot be **Restricted** — Team is the floor.</Info>
  </Tab>

  <Tab title="Change someone's role">
    Click the role dropdown next to a person in the Share modal (or the Access tab):

    * **Promote to Owner** on a User
    * **Demote to User** on an Owner

    The last Owner cannot be demoted or removed. Add a second Owner first.
  </Tab>
</Tabs>

***

## User Permissions

Eight per-agent switches that control what **Users** see. Owners always see everything.

<Frame>
  <img src="https://mintcdn.com/agenthub/skrs7CJFNw-SkKMP/images/agents/user_permissions.png?fit=max&auto=format&n=skrs7CJFNw-SkKMP&q=85&s=972f5fec99e3578bfc1b32b73c0a83ff" alt="User Permissions section with eight settings, each set to Show or Hide" width="420" data-path="images/agents/user_permissions.png" />
</Frame>

| Setting                    | Show means the User can                                           |
| -------------------------- | ----------------------------------------------------------------- |
| **Show Instructions**      | Read the instructions the agent follows (read-only).              |
| **Show Model**             | See which model the agent runs on.                                |
| **Show Connectors**        | See the connected apps the agent can use.                         |
| **Show Skills**            | See the skills the agent can use.                                 |
| **Show Knowledge Sources** | See the knowledge sources the agent can search.                   |
| **Show Subagents**         | See the other agents this agent can call.                         |
| **Show Secrets**           | See the **names** of the secrets the agent can use.               |
| **Create triggers**        | Create and edit their own triggers (**Allow** / **Don't allow**). |

Three rules worth remembering:

* **Visible is not editable.** Showing the instructions lets a User read the prompt, never change it.
* **Hiding something does not disable it.** Hide Connectors and the agent still uses Gmail — the User just doesn't see it listed.
* **Permissions are per agent, not per person.** Everyone with User access gets the same view.

<AccordionGroup>
  <Accordion title="Defaults and org-wide defaults">
    Out of the box every visibility setting is **Show** and **Create triggers** is **Allow**. Organization admins can ship different defaults with [Agent Default Settings](/enterprise-features/agent_default_settings).
  </Accordion>

  <Accordion title="What happens to existing triggers when you turn off trigger creation">
    If you switch **Create triggers** to **Don't allow** while Users already have triggers, Gumloop asks what to do:

    * **Keep running** — they keep firing. Users cannot create, edit, or activate triggers, but can still view, deactivate, and delete their own.
    * **Disable them** — they are switched off.

    Owners can still manage those triggers from the **Triggers** tab. Allowing creation again does **not** reactivate disabled triggers.
  </Accordion>
</AccordionGroup>

<Tip>
  **Example setup — an internal support agent everyone talks to:** General Access **Organization**, *Show Instructions* **Hide**, *Show Connectors* **Show**, *Create triggers* **Don't allow**.
</Tip>

***

## Task Visibility

A **task** is one conversation with the agent.

<Frame>
  <img src="https://mintcdn.com/agenthub/V62OUo6iBAfBS2AS/images/agents/task_visibility.png?fit=max&auto=format&n=V62OUo6iBAfBS2AS&q=85&s=dbcf652bcb69983e5883f5f042d08b6c" alt="Task Visibility section with the dropdown open, showing Their tasks only and Team tasks" width="480" data-path="images/agents/task_visibility.png" />
</Frame>

| Option               | What Users see                                                                                                |
| -------------------- | ------------------------------------------------------------------------------------------------------------- |
| **Their tasks only** | Each User sees only the tasks they created.                                                                   |
| **Team tasks**       | Users can **read** tasks created by team members. Continuing someone else's task still requires Owner access. |

* This setting only exists on **team agents**, and new team agents default to **Team tasks**.
* On a personal agent, Users see only their own tasks, so the setting is hidden.
* Owners always see every task on either kind of agent, and any task can also be shared separately.

<Note>
  Seeing a task includes its task-linked artifacts. It never grants access to another person's private persistent workspace files.
</Note>

***

## File Sharing

**Default behavior** sets sharing for every file the agent generates.

<Frame>
  <img src="https://mintcdn.com/agenthub/V62OUo6iBAfBS2AS/images/agents/file_sharing.png?fit=max&auto=format&n=V62OUo6iBAfBS2AS&q=85&s=dfb7c0dfee12340369997d6ca1f06c8d" alt="File Sharing section with the Default behavior dropdown open, showing Default, Organization, and Anyone" width="480" data-path="images/agents/file_sharing.png" />
</Frame>

| Option           | Generated files are shared with                                                                 |
| ---------------- | ----------------------------------------------------------------------------------------------- |
| **Default**      | Whoever can see the task and the agent — a file created in a team task is visible to that team. |
| **Organization** | Everyone in your organization.                                                                  |
| **Anyone**       | Anyone with the link.                                                                           |

See [Agent Artifacts](/core-concepts/agent_artifacts).

***

## Requesting and claiming access

<AccordionGroup>
  <Accordion title="Request Owner access" icon="hand">
    A User who needs to manage the agent opens the **⋮** menu in the agent header and chooses **Request Owner access**, then picks which Owner receives it. That Owner approves or denies it from their inbox. See [Request Owner Access](/help/sharing/request-owner-access).
  </Accordion>

  <Accordion title="Claim Ownership of a stranded agent" icon="crown">
    If an agent's Owners are unavailable, an organization admin in the same organization can manage it through administrative access and claim durable ownership. Claiming does not require every existing Owner to be gone: it changes the canonical creator and adds an Owner grant, and existing Owners remain. See [Claim an ownerless agent](/help/sharing/claim-an-ownerless-agent).
  </Accordion>

  <Accordion title="Organization admin access" icon="shield">
    Organization admins can reach any agent in the organization through their admin override, even without a grant. Admin access is **not** the same as being an Owner — that's why **Claim Ownership** exists.
  </Accordion>
</AccordionGroup>

***

## FAQ

<AccordionGroup>
  <Accordion title="Where did Editor, Viewer, and Use Only go?" icon="user-lock">
    They no longer apply to agents. An editor becomes an **Owner**; a viewer or use-only person becomes a **User** whose visibility you tune with User Permissions. Skills still use Editor, Viewer, and Use Only. See [Sharing a skill](/core-concepts/skills#sharing-a-skill).
  </Accordion>

  <Accordion title="Can a User edit the instructions they can see?" icon="pen">
    No. Every User Permission is about seeing, not editing. Editing the agent requires Owner.
  </Accordion>

  <Accordion title="Can I give one person more access than another?" icon="users">
    Not today. User Permissions are per agent, not per person. If one person needs more, make them an Owner, or make a copy of the agent with different settings.
  </Accordion>

  <Accordion title="Why can I not remove the last Owner?" icon="crown">
    An agent always needs someone who can manage it. Add a second Owner first, then demote or remove the original.
  </Accordion>

  <Accordion title="Someone left the company and their agent is stuck" icon="user-slash">
    An organization admin can open it and use **Claim Ownership** to take it over.
  </Accordion>
</AccordionGroup>

***

## Related

<CardGroup cols={2}>
  <Card title="Agents" icon="robot" href="/core-concepts/agents">
    The agent builder, tab by tab.
  </Card>

  <Card title="Agent Triggers" icon="bolt" href="/core-concepts/agent_triggers">
    Who can create triggers, and what happens when you turn that off.
  </Card>

  <Card title="What can a User see on my agent?" icon="eye" href="/help/sharing/what-can-a-user-see">
    Quick answer with the eight settings.
  </Card>

  <Card title="Sharing Roles" icon="users" href="/help/sharing/sharing-roles">
    Owner vs User, and roles on skills.
  </Card>
</CardGroup>
