Skip to main content

Sharing and permissions

Who can share agents​

You will be able to share your agents with others if:

Sharing and publishing are separate permissions. Editor access lets a user edit an agent, but it doesn't by itself allow the user to publish the agent.

Who can publish agents​

You can publish an agent if one of the following applies:

  • You are an admin or agent moderator
  • You have the Agent Creator role and can edit the agent. Agent creators can publish private, shared, and company-wide agents, regardless of the default-member publish settings.
  • As a default member with agent-create permission, you can publish private agents. For shared and company-wide agents, the applicable default-member sharing or publishing setting also has to allow it.

A default member without agent-create permission can't publish an agent, even if they have editor access.

How to share an agent​

In the agent builder, click Share in the header. You can share an agent with individuals, departments, and identity provider groups when your admin has enabled group sharing. Each agent has one owner who is responsible for it.

Admins and Agent Moderators can share with all groups from the configured identity provider. Default members can share with groups they belong to when the admin enables the corresponding default-member permission. See Share agents with identity provider groups for setup details.

note

Your admin sets the maximum audience you can share an agent with. Depending on this setting, you can share with specific people, people in your department, configured identity provider groups, or everyone in your organization. The Share dialog shows only options within this limit. If your admin tightens the limit, existing shares remain unchanged, but new shares follow the updated limit.

Transfer ownership​

Only the current owner, Agent Moderators, and Admins can transfer ownership.

To transfer ownership:

  1. Open the agent in the Agent builder and click Share.
  2. Select the individual who should own the agent.
  3. Confirm the ownership transfer.

The new owner gets Owner access. The previous owner becomes an Editor and keeps edit access unless you remove it separately. The agent's creator history does not change when ownership transfers.

You can share an agent with departments and identity provider groups, but you can't assign them Owner access. Grant these audiences Viewer or Editor access instead.

Auto-generate agent description​

When you share an agent that does not have a description, Glean automatically suggests an icon and an AI-generated description. You can review, edit, or replace the suggested description before confirming the share.

This feature helps keep the agent library organized and makes it easier for users to understand what each agent does. Descriptions remain optional—you can still share agents without one—but the auto-generation workflow reduces friction and encourages best practices.

To use autogenerated descriptions:

  1. Open the Agent Builder and click the Share button when you're ready to share your agent.
  2. If your agent doesn't have a description, a modal appears with a suggested icon and autogenerated description.
  3. Review, edit, or replace the suggested description.
  4. Confirm the share to save the description.
tip

You can also use the Enhance button (sparkle icon) next to the description field in Agent Settings to generate or refine a description at any time, even after saving.

The table below shows the capabilities that are granted by each permission.

No AccessViewerEditorOwner
See agent in the libraryNoYesYesYes
Run agentNoYesYesYes
View configuration of agentNoYesYesYes
Edit agentNoNoYesYes
Change permissions of agentNoNoYesYes
Delete agentNoNoNoYes
Transfer ownershipNoNoNoYes
note
  • You can grant the Editor permission to users who collaborate with you on building an agent. Editors can edit your agent even if your admin did not give them permission to create agents.
  • An agent can have only one owner at a time. The current owner, Agent Moderators, and Admins can transfer ownership.
  • Super admins and Admins have the Owner permission on all agents at the company.
  • These permissions will be enforced everywhere, including if the agent is called via Slack or the API.

Existing agents with multiple owners​

Glean is transitioning agents to a single-owner model.

When this change is enabled, Glean automatically sends co-owners an advance notice email specifying the affected agents and the two-week migration timeline.

How to resolve ownership before the deadline: Before the migration date, an owner or admin can open Share for any affected agent and select a single primary owner.

Automatic migration fallback: Receiving the advance notice email does not change permissions immediately. However, if no one manually updates ownership before the migration date, Glean automatically assigns a single owner using the following rules and changes all other co-owners to Editors:

  • If the agent creator is still an owner: The creator remains the primary owner.
  • If the creator is no longer an owner: Glean selects the remaining owner whose name comes first alphabetically.
note

Creator history remains unchanged regardless of who becomes the primary owner.

When an owner is deactivated​

When an agent owner is deactivated, Glean reassigns ownership to that person's manager. If manager information is unavailable, Glean assigns the agent to an Agent Moderator. The new owner receives an email notification and can transfer ownership again if needed.

Document access across surfaces​

The document access an agent uses depends on where it's invoked and how it's configured.

In the Glean web app, the agent uses the signed-in user's individual permissions. The agent can reference any document that the user has access to, so responses are personalized to each user.

In Slack, permissions depend on the visibility setting you choose when publishing the agent to Slack:

  • Only visible to user (with or without the option to share): The agent uses the requesting user's individual permissions, similar to the web app experience.
  • Visible to everyone in the channel: The agent uses a broad-access model rather than your personal permissions. By default, it can reference public content across your organization and messages from the current Slack channel, if recognized. It does not check if every member of the channel has permission to view each document. Depending on the settings of your organization, it may also include approved code repositories.

This model prevents private or restricted content from accidentally being shared in public channels.

Troubleshooting different responses across surfaces

If an agent produces different or more limited responses in Slack compared to the web app:

  • To align Slack behavior with the web experience, change the agent's Slack publishing setting to "Only visible to user" with an option to share. This lets the agent use each user's individual permissions.
  • To keep responses visible to everyone, ensure that the reference documents for the agent meet the broad-access requirements of Option C. See Publishing to Slack.

Publishing options​

The share panel displays additional publishing options only when they apply to the selected agent:

Slack (agents with chat message triggers only)​

Publishing an agent to Slack enables users to interact with the agent directly within Slack, allowing the agent to respond to messages, perform tasks, or provide information in Slack channels.

Publishing agents via API​

Publishing an agent programmatically exposes its capabilities, allowing external software systems to invoke its logic and receive results. This enables seamless integration with custom workflows and third-party applications.

Generating a token​

Eligible users can generate a Client API token directly from the Share → API panel of the agent.

Tokens created through this panel are automatically scoped exclusively to that specific agent. This restriction follows the principle of least privilege, allowing you to safely call the agent from a script or integration without granting access to every agent available to your account.

Security and maintenance​

  • Critical: The token secret is displayed only once during creation. Copy and store it securely in a password manager or vault before leaving the page; it cannot be recovered.

  • Expiration: Scoped agent tokens automatically expire one year after creation.

  • Rotation: To rotate a token, you must delete the existing token and create a new one.

For more information, see API tokens.