Skip to main content

Working in a governed deployment

A governed deployment is a Studio where everyone assigned works on the same resources. Standard or governed is chosen once, when an administrator creates the deployment, and cannot be changed later (Deploy your first Studio). If you never see the chip below, you are in a standard deployment, where each user sees only their own resources and files.

Recognise it​

A slim strip with a shield at the top of the main column reads Governed deployment · resources are shared by everyone assigned. Hovering it: "Everyone assigned sees, creates, edits, versions and runs the same agents, workflows, connectors, environments and knowledge graphs, and can open and download every user's workspace files. Your own files land in your own folder."

What is shared​

  • Resources: every agent, workflow, data connector, execution environment and knowledge graph appears in everyone's lists, whoever created it; you create, edit, version, share, run and delete with the same controls and guards as in a standard deployment. A resource has one active version for the whole deployment: the workflow version you activate is what everyone's Run Now, schedules and API keys use. An agent can pin any connector, environment or graph in the deployment.
  • Files: in Chat's Files tab and on a run page the scope gains Everyone's files ("every user's workspace in this deployment, grouped by owner. Open and download anything; new files still go to your own folder."), one root per user, yours labelled You · and your e-mail address. Open, preview and download anything; every write (uploads, new folders, files your agents produce, run outputs) lands in your own folder, and a write under another root is refused: "This folder belongs to another user. You can open and download anything here, but new files and changes go in your own folder only."
  • Runs and approvals: Workflow Runs lists every run in the deployment, including API-started ones; you can open any and stop those still going. Approvals raised by API-started runs appear in everyone's Inbox with an API run badge ("Raised by an API-triggered run. Everyone assigned to this deployment sees it; whoever acts is recorded on the run.").
  • Attribution: every create, edit, activation and deletion records the user (a workflow's Metadata shows Created By and Updated By); every run records who started it, API-key runs showing the key in the Trigger chip; approving, sending back or stopping is recorded against you.

Notes​

  • Reads are shared, writes never are: nothing can be created, changed, moved or deleted inside another user's folder.
  • The per-user limit of 256 workflows (and 256 of each other resource type) counts what you created; because lists show everyone's, Create is not greyed out in advance and the server refuses at your cap with its own message.
  • The default PII redaction is Mask, which a workflow may tighten but not loosen (PII redaction). Governed deployments alone offer programmatic access (Trigger from outside).
  • "This folder belongs to another user. …": switch to This conversation, This run or All my files, or upload into your own root under Everyone's files. "Could not list the deployment's files.": refresh, or switch to your own scope. "Preview is rendered in the owner's folder only": another user's Office document cannot render in your preview; download it.