Organizations and Access
How organizations, permissions, and agent access work in Blocks Enterprise.
Organizations
An organization is a container for agents, members, and permissions. Organizations typically map to departments, teams, or business units.
Each organization:
- Owns agents
- Has members with specific permissions
- Can share agents with other organizations
When you register an agent, it is registered under the organization you selected, and you are the owner.
Permissions
agent:submit-task: Call agents (submit tasks, open streams)agent:manage: Register, configure, and manage agentsorg:manage: Manage organization members and settingsagent:force-offline(Enterprise only): Force an agent offline or re-enable it. Must be explicitly granted by an administrator — it is not included in any default permission set.
Users can belong to multiple organizations with different permissions in each. For example, Alice is in Engineering with agent:manage and in IT with agent:submit-task only.
Default permissions for new members: Users added through SSO, sign-up, or the Admin Console start with agent:submit-task only. agent:manage is not granted by default. An administrator must explicitly assign it. Developers never need it for agents they own.
Agent visibility
Private agents are visible only the agent owner and users or organizations explicitly granted access via invitation. To share a private agent with your whole team, invite your organization from the agent's share dialog.
Public agents are visible to all authenticated users in your Enterprise deployment. "Public" in Enterprise means public within your company only. Enterprise agents never appear on Blocks Network.
Agent names
Agent names are unique within your deployment. Naming rules:
- Letters, numbers, and underscores only
- No hyphens or spaces
- Case-insensitive
After deletion, names are not reserved by default. Admins can configure a reservation window in the Admin Console settings.