Skip to main content

Manage action access

When you enable an action pack in Admin consolePlatformActions, you can restrict which users or groups can invoke those actions in Chat and agents. This is called visibility scoping and is separate from who can configure actions in Agent Builder.

Two distinct access controls

Admin configurations control two entirely separate layers of access: who can use the action versus who can build with it.

SettingWhat it controlsWhere to configure
Visibility scopeDictates which end users can see and invoke the action within Chat or agentsAdmin consoleActionsEdit settingsMake available to
Role-based accessDictates which admins and builders can view and add this action when constructing an agentAdmin consoleActionsManage role-based access

This page covers visibility scope only. For builder-level access, see Managing action access.

How visibility scoping works

By default, when you enable an action pack, it's available to everyone in your Glean workspace. You can restrict this to specific users, departments, or groups.

End-user experience outside the visibility scope

If a user falls outside the visibility scope of an action but attempts to trigger it, the system behavior depends on the interface:

  • In Glean: The action is completely hidden. It does not appear as an available tool, and Glean will ignore explicit user requests to invoke it.
  • In Agents: If the agent is shared with the user, the specific action step fails silently. The agent will bypass the step and attempt to complete the remaining workflow.

Configure visibility scoping

  1. Navigate to Glean Admin console.
  2. Click Actions.
  3. Click the action pack you want to configure and navigate to the Configuration tab.
  4. Click Edit settings under Enable actions.
  5. Under Make actions visible for all or some teammates, select either:
    • Agent
    • Chat
  6. Under Access change the scope to:
    • All teammates
    • Specific department name
    • Specific teammate name
  7. Click Save. The changes take effect immediately.

To ensure a secure and stable deployment, expand the visibility scope of your action progressively using the following phased approach:

StageRecommended scope
Initial pilotSpecific users — limit to your test group or IT and ops team
Departmental rolloutSpecific departments — for example, Engineering only for Jira actions
Full rolloutEveryone

Visibility scope vs agent sharing

If an agent uses an action that's scoped to specific users, the action only executes successfully for users within that scope — even if the agent itself is shared more broadly.

warning

A Jira agent shared with the entire company but backed by a Jira Extension Actions pack scoped to Engineering only will fail the Jira action step for non-Engineering users. Either broaden the action's visibility scope or narrow the agent's sharing scope to match.

Troubleshooting

For questions and support, reach out to the Glean support team.