Organizations & policies
Your organization is Imaginne's tenant. Everything you do happens in its context: your identity carries your organization, and the organization's policy governs what the agent can do for you.
What policy controls
Policy is the set of rules the organization defines. It governs, among other things:
- Allowed models and which one is the default — what shows up in your picker.
- Credential source — whether to use the shared platform key or the organization's own key (BYOK).
- Enabled skills — which capabilities enter the agent's list for you.
- Execution — whether the agent may run commands, run local skills, and write outside the workspace.
- Content and data — language, tone, rules about sensitive data.
How the rules combine
Policy is assembled in layers, from the most general to the most specific:
- Platform — the baseline.
- Organization — your company's rules.
- User type — the account tier.
- Skill group — per-group rules.
- Profile — the most specific, tied to you.
The layers combine with deny-wins: a more specific level can restrict the base, never broaden it. The result is the effective policy the agent receives each session.
Profiles: the link between people and skills
The set of skills you see is the union of the skills of the profiles assigned to you. A practical consequence:
A user (even an administrator) with no profile assigned sees no skills in the session. Administrators need to assign a profile to themselves to use the chat surfaces. See Profiles.
Roles
The organization has distinct roles:
| Role | Can |
|---|---|
Organization administrator (org_admin) | Manage everything: users, profiles, groups, skills, policies, keys, secrets, templates, audit. |
Skill administrator (skill_admin) | Manage skills within the groups under their responsibility. |
User (member) | Use the agent according to policy; goes straight to the chat. |
See Users & roles.
User types
There are account types (premium and full) that exist in policy. Today both have an identical permissive baseline — differentiation by type is a feature for future evolution. Don't count on behavioral differences between them for now.
Where this is configured
Everything above is administered in the /app console. Start with Administration — overview and Governance & policies.
See also
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.