Permissions and approvals
How much an Agent checks with you, standing authority, seats, and spend.
Every member can create Agents. Organization roles determine who manages members and billing; each resource has its own sharing settings.
Agents
Every active Agent has an owner. Read lets you chat with it and view its conversations and Automations. Write also lets you manage its instructions, settings, and schedules. The sharing panel shows direct grants and rooms where people can interact with the Agent.
An Agent can inspect the resources its owner can inspect, including personal Connections. It needs its own grant to each Computer. Sharing an Agent lets other people ask it to use that authority, subject to its judge instructions; it doesn't give those people direct access to the underlying resources.
Automatic approval review
Runva reviews consequential tool calls automatically. Agent managers can set judge instructions and standing allowances under Without asking. Review uses the requester's verified identity and whether they can manage the Agent. Only someone with Agent Write can approve lasting configuration changes or choose Allow next time. A one-time approval doesn't grant editing rights.
Personal and Team Connection tools use the same on/off controls. Disabled tools stay unavailable; enabled tools follow ordinary automatic review.
Computers
A Computer has a responsible person and separate grants for people, teams, and Agents. Read allows using its software, files, browser, and desktop. Write also allows changing its configuration in Runva. Local and cloud Computers follow the same permission rules.
People and Agents can use an authorized Computer at the same time. Power changes and scheduled management use ordinary judge review. The working folder is guidance for the Agent, not filesystem confinement; operating-system permissions still apply.
Docs and Skills
Docs inherit access from their parent: Can view, Can comment, Can edit, or Full access. Full access includes managing sharing. A private root keeps Docs private until someone grants access.
Each Skill has an owner. Private Skills are for the owner; Shared Skills are available throughout the Space but only the owner can edit them; Space Skills can be used and edited by every member. These permissions also apply to drafts.
Spending and ownership
Admins assign member spending ceilings. Agent managers can allocate limits within the owner's ceiling. Members see their own usage; owners and admins can view organization billing and cross-member reports.
An Automation that creates its own Thread can have a dollar budget that lasts across Runs in that Thread. Agent managers can change it. Room Automations use the Agent, member, and organization limits without a separate budget. There are no customer-facing step limits.
When someone leaves, an admin transfers their Agents or archives and disables them. Archiving stops active work immediately. During transfer, the admin chooses whether active Runs continue or stop. Computer access doesn't widen and ownership history remains available.