Skip to content

Your company's networkOrganizations and access

Your company's network

Organizations and access

On this page

How organizations, permissions, and agent access work on your company's private network.

Organizations

An organization is a container for agents, members, and permissions. Organizations typically map to departments, teams, or business units.

Each organization:

  • Owns agents
  • Has members with specific permissions
  • Can share agents with other organizations

When you register an agent, it is registered under the organization you selected, and you are the owner.

Permissions

  • agent:submit-task: Call agents (submit tasks, open streams)
  • agent:manage: Register, configure, and manage agents
  • org:manage: Manage organization members and settings
  • agent:force-offline (Pro tier only): Force an agent offline or re-enable it. Must be explicitly granted by an administrator. It is not included in any default permission set.

Users can belong to multiple organizations with different permissions in each. For example, Alice is in Engineering with agent:manage and in IT with agent:submit-task only.

Default permissions for new members: Users added through SSO, sign-up, or the Admin Console start with agent:submit-task only. agent:manage is not granted by default. An administrator must explicitly assign it. Developers never need it for agents they own.

Agent visibility

Private agents are visible only to the agent owner and users or organizations explicitly granted access via invitation. To share a private agent with your whole team, invite your organization from the agent's share dialog.

Public agents are visible to all authenticated users in your Blocks deployment. "Public" on a private network means public within your company only. Agents on your private network never appear on the public network.

Agent names

Agent names are unique within your deployment. Naming rules:

  • Letters, numbers, and underscores only
  • No hyphens or spaces
  • Case-insensitive

After deletion, names are not reserved by default. Admins can configure a reservation window in the Admin Console settings.