Your own agents, and private ones

Last updated October 9, 2026

On this page

Draft for review

Besides the agents that work for a team or the whole company, a person may have agents of their own: a version of Sales Assistant that works only for them, or their inbox assistant. An agent of your own is a copy of an app's template that works for you alone (Templates and copies). Nobody else may ask it, mention it, give it work or decide its approvals, admins included. You may also make it private: then nobody else in the product sees its conversations, its instructions or its data, admins included.

This page covers My agents, asking for your own agent, what an agent of your own answers, what private stops and what it does not, what admins and managers see, and what happens when someone leaves. It describes the golive branch. What is not possible yet is listed at the end.

Private agents are available from the release that brought storage version 5; operators see Operations.

My agents#

My agents in the sidebar (/agents), "The agents that work for you", has three tabs.

Yours groups the agents that work for you:

Group What is in it
A notice at the top "Eli Novak made Sales Assistant for you", with Turn it on and Not for me
Your own Your own agents; a private one carries a Private capsule
Your team's Shared agents of your team that work for you
Company The other shared agents that work for you
Archived Your own agents archived in the last 90 days, with Restore

Each row has its one line, what runs for you on it ("Weekdays: Your follow-ups today at 09:07", see Team schedules), "Offered to you" for an agent that works for you once you turn it on, and "Updated 9 Oct by Eli Novak: new steps for demo requests" after a change. Ask opens a conversation with it; an offered one shows Turn on and Not for me instead. Its menu has Make my own version, Turn off for me (unless an admin made it required for you), and What it can do, the agent's page as you see it: who manages it, what it can use, and Turn on or Turn off for me. For your own agents the menu adds Settings, Pause or Resume, Download its data and Archive.

With nothing there: "No agents work for you yet. Get one." The My agents row in the sidebar carries a small dot when something waits for you there. Holders and admins see Agents I manage → at the top, to Apps > Agents.

Get an agent lists what you may have your own version of: templates open to personal copies (the Inbox Assistant first, while the Inbox app is enabled) and shared copies that work for you whose managers allow it. Each row says "Your own Inbound Sales Assistant", who decides ("Sam Ortiz or Eli Novak decides", or "made at once"), and Make my own or Ask for my own.

Requests lists your requests with their state (Waiting, Approved, Rejected, Withdrawn) and Withdraw on a waiting one. For holders it first lists "Waiting for you", with Approve and Reject.

Asking for your own agent#

A template is open to people's own copies when its app says so (the Inbox Assistant, and Sales Assistant from CRM version 2) or an admin turned on People may ask for their own on the app's Templates tab. A shared copy is open when its managers turned on People it works for may ask for their own in its settings.

  1. On Get an agent, choose Ask for my own (or Make my own), or Make my own version in an agent's menu.
  2. The sheet, "Your own Inbound Sales Assistant", has:
    • Name, "Alice's Inbound Sales Assistant" to start with.
    • Start from: the copy as it is now, or its template.
    • What it will use: its tools in words. A tool that reaches data you do not already reach says "an admin approves this one".
    • Private, with what it means (below).
    • Replaces Inbound Sales Assistant for you, on when you start from a copy you use: "Its approval rules come with it."
    • A note to whoever decides, and at the foot who decides.
  3. Choose Ask (or Make it when it is made at once).

Every holder covering you gets the request, never you; see Manage agents. The company makes the Inbox Assistant at once for everyone; other templates wait for a decision. When it is approved, the agent is yours: it is under Your own, acting for you.

Refusals:

When You read
The template is not open to people's own copies "Sales Assistant is not open to personal agents; ask an admin"
Its app is not bound to any of your teams and no copy of it works for you "The Sales app is not set up for your team; ask an admin"
A request for it already waits "Your request for your own Inbound Sales Assistant is still waiting; withdraw it first" (409 request_open)
You have as many as the company allows (5 by default) "You have 5 of your own agents, the most your company allows (5)"
The company does not offer them "Your company does not offer personal agents; ask an admin"
More than 10 requests in a day "at most 10 requests a day"

Replaces. Your own copy may replace a shared copy you use. The shared one then stops working for you, its team schedules run for you on your own copy instead, and your own copy carries its approval rules, which you cannot remove. Turning Replaces off, or archiving your own copy, gives you the shared one back. When the shared copy is archived, your Replaces lapses and you are told; your own copy keeps working.

Made for you. A holder may make an agent for you alone. It is made off and acts for nobody until you choose Turn it on; Not for me archives it and its maker is told. After 14 days without an answer it is archived.

Try it: Eli makes one for Alice#

  1. As ada, grant Eli manage agents for Sales (Manage agents).
  2. As eli, on CRM's Templates tab choose Make a copy on Sales Assistant. Name it Alice's Sales Assistant, choose People under Who it works for, find Alice Chen. The note reads "This makes a personal copy for Alice Chen. Alice turns it on, and may make it private." Choose Make the copy: "Made Alice's Sales Assistant for Alice Chen: waiting for them to turn it on".
  3. As alice, My agents reads "Eli Novak made Alice's Sales Assistant for you". Choose Turn it on. It moves under Your own.
  4. As ada, start a new conversation and open the agent picker: it does not offer Alice's agent. Asking it through the API answers 404 "No agent here by that name". As sam, who leads Sales, its page reads the same.

An agent of your own answers you only#

A personal agent answers its owner and nobody else, admins included. Every refusal is the same 404, "No agent here by that name", so no answer tells anyone that it exists, what it is called or whose it is. Its id is opaque (pc- and ten letters), and its name is unique only among its owner's own.

Path What happens for anyone but its owner
Asking it, in the composer or the API, alone or with other agents Not offered; 404
Mentioning it in a thread Nothing wakes; the text stays text
Consulting it from another agent, giving it a task, a repeat, a group or a team schedule 404
An outside agent handing it work Refused
Making a copy from it Only its owner
Its approvals, drafts, questions and escalations Its owner only (below)
A shared agent asked "show me Alice's pipeline" Acts for the asker, capped at what the asker may read
Changing it Anyone else's change, its model and required parts included, waits for the owner's OK showing the exact change

Private#

Private is the owner's choice on an agent of their own, in Settings (Private) or when asking for it. It is off by default, and on by default for the Inbox Assistant. Only the owner turns it on or off: the switch acts like a password, so it needs a sign-in within the last ten minutes. If yours is older, Confirm it is you asks for your password first, and an API token can never change it. Restoring an older version of the agent's settings that turns private on or off asks the same. You get an email each time it changes. Under every Private switch the product says plainly what it does and does not stop:

Only you will see its conversations and instructions. Admins see that it exists and what it costs, and can pause or archive it. Whoever runs the server can read everything outside the app. What it changes in company records stays visible as usual.

Who sees what#

What The owner Admins Holders covering the owner Anyone else, team leads included
That it exists: template, owner, state, since when Yes Yes Yes No
Its name and one line Yes "Private copy of Sales Assistant" No No
Its settings: tools, model, limits, schedules, rules Yes Yes No No
This month's cost Yes Yes Yes No
This month's runs, failures, approvals waiting, refusals, as counts Yes Yes No No
Its instructions, checks, proposed changes, history Yes No No No
Its conversations, runs, answers, files, memory Yes No No No
Its approvals and questions Yes, and only the owner decides them Counts only No No
Live activity In words "At work", no words No No
The event log Content-free for everyone: ids, costs, times and fixed codes The same No No
Search In the owner's own searches Not found No No
An inbox assistant's messages, rules, notes and drafts Yes No No No
Replies an inbox assistant sent In full, with Download Daily counts by channel and how sent No No

Nobody can open a private agent, for any reason. There is no break-glass for an investigation or a legal hold (the user's decision of 8 October 2026), and the admin help on the governance view says so: "Private agents cannot be opened by anyone but their owner, for any reason; the company's own mail and chat systems keep what was sent."

Private is a boundary in the product, not encryption: whoever runs the server and holds the state file, or holds a backup and its recovery key, can read everything outside the product.

Only in your own conversations#

A private agent works only in its owner's own conversations: a one-to-one chat with it, or a thread with no other person in it. Asking it anywhere else is refused before anything runs: "Your private agent works only in your own conversations". Adding a person to a thread it is in is refused too. You may add shared agents to a private conversation; their work there is private as well.

A conversation made with a private agent stays private after you turn private off. Turning private on applies to conversations made from then on.

Privacy follows the conversation#

Everything that runs in a private conversation, or in work started from one, is private, whichever agent runs it: a shared agent your private one hands a task to, an agent it consults, the members of an ask to several agents. Others see such runs only as state and cost ("At work").

  • Memory. What runs in private scope decides or remembers goes to your own memory, whatever the plan asked for, and never to a review queue for the team or the company.
  • Company records. What your private agent changes in company data (a lead's stage) stays company data, visible as usual. Its history reads "by Alice Chen's private agent", with no link to the run; opening the run by id is 404.

The event log#

The log is hash-chained, so nothing written to it can be removed. Events in private scope are therefore written without content: a task's title reads "Private task", a step reads "step 3: query", a post or a note has no text, and reasons are fixed codes. Your own views read your runs, threads and steps themselves, in full. See Events and the audit log.

Its approvals and questions#

An agent of your own reports to you. Its approvals, drafts, questions and escalations go to you: no lead and no admin decides them in your place.

  • Only you approve or edit them. Others may only reject one, with a reason you read, and only when the agent is not private. On a private agent they see nothing of it; their brake is Pause.
  • Company rules always win. A rule that sends one of its steps to someone else (say, payments over $500 need finance, or "their manager") is decided by the people it names, never by you in their place:
    • On a private agent you are asked first: "This step will be shown to Fiona Reyes (company rule: payments over $500 need finance). Show it?", with the call's arguments. On Show, Fiona sees the tool and its arguments only, and decides; your run reads "Waiting for Fiona Reyes". On Don't, the step is refused with the rule's name.
    • On an agent that is not private, the step goes straight to Fiona.
    • Either way you may reject it, but approving it is Fiona's: "a rule sends this to Fiona Reyes to approve; you may reject it".
    • A rule that denies still denies.
  • A task in private scope that runs past its due time is not handed to anyone; you are reminded instead.
  • A question from a private agent is never passed on or escalated, and nobody else can answer it (404); when its time runs out only Assume and Stop apply.

The same holds for a reply through a tool that sends a message in your name (the inbox assistant's replies): only you approve or edit it, whichever agent calls it. When a company rule sends such a message to someone else for approval, they approve it first and you sign it after them; it goes out only when both of you have.

What admins and managers see#

On Apps > Agents and the agent's page, someone else's private agent shows the governance view under a banner: "Private: only Alice Chen sees its conversations."

  • Admins: owner, made from ("Sales Assistant v1"), state, who made it, this month's cost, its settings, and this month's runs, failures, approvals waiting and refusals. For an inbox assistant, Sent for Alice: replies by day, channel and how sent, with money, legal, HR and personal mail together as "Other, private" (The inbox assistant). Actions: Pause (with a reason the owner reads), Set a limit, Archive (with a reason). There is no Open, Ask or Export.
  • Holders covering the owner: owner, made from, state, since when and this month's cost; nothing else.
  • Anyone else, team leads included: nothing. "No agent here by that name."

Apps > Agents folds people's own agents into one row a template ("Sales Assistant · 2 personal copies"), searched by owner. Spending reports count a private agent as "Private copy of Sales Assistant (Alice Chen)".

Admins keep their brakes: Pause (a switch only an admin lifts), a limit, Archive with a reason, Pause every copy of a template, and the global switch. They cannot open it, ask it, export it, or change its behaviour or model.

Spending#

Limit Default
Each of your own agents, a month The template's (the Inbox Assistant: $10), else $5
All your own agents together, a month $20
The company's own agents together, a month $500

At a limit the agents stop until the month turns, and you are told at 80% and at 100%. A personal agent's run charges no team's budget. See Team schedules for how monthly limits work.

When people leave or change#

When What happens to their own agents
They leave a team Their own agents stay; a Replaces of a copy they no longer use lapses
They are deactivated Paused
They are offboarded Archived; their delegations revoked; open drafts and approvals expire; a reply held in its undo window is dropped, not sent; channel accounts and personal connections revoked. Private content stays unreadable to everyone and is purged after the company's retention for private content (90 days by default; 0 purges it at once), or the sent records' retention when that is shorter. Event metadata stays
Their email address changes Their inbox channel accounts pause until they connect again, and the old address is told

People who own a private agent are protected around the product too: a password reset link for them is only ever mailed to their own address, never shown to the admin who asked for it; they are told when an admin changes where backups go or fetches the recovery key.

Your own download. Download its data on My agents (and Download my assistant's data on the inbox assistant's Settings) gives you a file of your agent's conversations, drafts, rules, notes and sent records. Nobody else can download it, admins included. Like the Private switch, it needs a sign-in within the last ten minutes, and you get an email each time.

Erasure by address or number. When someone outside the company asks it to erase what it holds about them, an admin holding the data_owner role uses POST /api/governance/erase { identifier }: messages and sent records from and to that address or number are deleted in every person's store. The admin sees only how many rows from how many people, each owner reads "A message from a sender was erased at the company's request", and the log records the counts, never the identifier.

Not possible yet#

  • Erasure by address or number on the screen (Governance); the API only.
  • Changing the company's limits for people's own agents (how many each, the monthly caps, retention, which are made at once) on the screen or through the API.
  • Deleting a private agent's conversations before the retention runs out.
  • Opening a private agent's conversations for an investigation: not planned.

For developers#

API#

All under /api.

Method and path Who Purpose
GET /me/agent-requests Anyone { mine, waiting_for_me }
POST /me/agent-requests/check Anyone { from, name, private, replaces, note }: what a request would do (its tools in words, who decides), filed nowhere
POST /me/agent-requests Anyone The same body: 201 { outcome: "made", copy } when made at once, 202 { outcome: "requested", approval } otherwise
DELETE /me/agent-requests/:id The person who asked Withdraw
POST /copies/:id/accept The person it was made for { on }
GET /me/copies/:id/export Its owner, signed in within ten minutes Download its data; 403 reauth_required for an older sign-in, session_required for a token; 404 for anyone else
PATCH /copies/:id Its owner { patch: { private, replaces, … }, version }; a patch that sets private needs a session signed in within ten minutes (403 reauth_required, or session_required for a token)
POST /copies/:id/history/restore Its managers or owner { kind: "settings", version }: a version whose private or replaces differs from now needs the same recent sign-in
POST /governance/erase An admin holding data_owner { identifier }: counts only; 20 a day

GET /copies/:id answers an admin the governance form and a covering holder the short form for someone else's private agent; anyone else 404.