Skip to main content

Allowed resources

An agent only reaches what the space allows. This is the product's governance surface.

The four categories​

CategoryWhat it isWho runs it
Flow actionsDeterministic steps: calling an API, running an automationAgents itself
AI resourcesWhat an AI task may use: search, integrations, capabilitiesImaginne's engine
SkillsThe organization's skillsImaginne's engine
ConnectionsAccounts connected to external systemsImaginne's engine

They do not mix: a flow action step accepts only actions; an AI task accepts only AI resources and skills.

Allowing​

In the space's configuration, each category has two lists: what exists and what is allowed. Moving an item from left to right makes it available to that space's agents.

Only what genuinely exists in this installation appears in the list — not a list of intentions.

The states​

StateMeansAction
AvailableIt exists and is allowedNone
Not allowedIt exists and the space has not allowed itAllow it here
UnavailableIt does not exist in this installationNone on your part
Not confirmedIt could not be checked right nowCheck again

"Not confirmed" never becomes "does not exist". The two would lead to opposite decisions: one calls for waiting, the other for redesigning the agent.

Allowed HTTP addresses​

Beyond the categories above, the space keeps a list of addresses the agents may call. An address outside it is refused at publishing time, not on the first run.

Secrets by reference​

Credentials used by agents are declared as a reference to a secret, never as a value. The published definition keeps the reference; the value lives in the vault.

An attempt to write a credential straight into a header is refused at publishing time — it would go into the immutable version and never come out.

A production-only secret is refused in development.

What revoking reaches​

Removing a resource from the space applies to later publications. A version already published and active carries what was declared in it — removing the resource now does not interrupt what is running.

To genuinely stop it, deactivate the active version.

There is no "who uses this?"

There is currently no query that answers which agents use a given tool. When you remove a resource, the product does not warn who will be affected in later publications. Check before removing.

The space's ceilings​

The space also defines the ceilings a definition may declare. See Limits.

Next steps​