Skip to main content

Organizations & policies

Your organization is Imaginne's tenant. Everything you do happens in its context: your identity carries your organization, and the organization's policy governs what the agent can do for you.

What policy controls​

Policy is the set of rules the organization defines. It governs, among other things:

  • Allowed models and which one is the default — what shows up in your picker.
  • Credential source — whether to use the shared platform key or the organization's own key (BYOK).
  • Enabled skills — which capabilities enter the agent's list for you.
  • Execution — whether the agent may run commands, run local skills, and write outside the workspace.
  • Content and data — language, tone, rules about sensitive data.

How the rules combine​

Layers (platform, organization, user type, skill group, profile) combine into an effective policy.
The layers stack by precedence (deny-wins): each level can restrict, never broaden the base.

Policy is assembled in layers, from the most general to the most specific:

  1. Platform — the baseline.
  2. Organization — your company's rules.
  3. User type — the account tier.
  4. Skill group — per-group rules.
  5. Profile — the most specific, tied to you.

The layers combine with deny-wins: a more specific level can restrict the base, never broaden it. The result is the effective policy the agent receives each session.

The set of skills you see is the union of the skills of the profiles assigned to you. A practical consequence:

No profile, the chat opens empty

A user (even an administrator) with no profile assigned sees no skills in the session. Administrators need to assign a profile to themselves to use the chat surfaces. See Profiles.

Roles​

The organization has distinct roles:

RoleCan
Organization administrator (org_admin)Manage everything: users, profiles, groups, skills, policies, keys, secrets, templates, audit.
Skill administrator (skill_admin)Manage skills within the groups under their responsibility.
User (member)Use the agent according to policy; goes straight to the chat.

See Users & roles.

User types​

There are account types (premium and full) that exist in policy. Today both have an identical permissive baseline — differentiation by type is a feature for future evolution. Don't count on behavioral differences between them for now.

Where this is configured​

Everything above is administered in the /app console. Start with Administration — overview and Governance & policies.

See also​