Your own agents, and private ones
Last updated October 9, 2026
On this page
- My agents
- Asking for your own agent
- Try it: Eli makes one for Alice
- An agent of your own answers you only
- Private
- Who sees what
- Only in your own conversations
- Privacy follows the conversation
- The event log
- Its approvals and questions
- What admins and managers see
- Spending
- When people leave or change
- Not possible yet
- For developers
- API
Draft for review
Besides the agents that work for a team or the whole company, a person may have agents of their own: a version of Sales Assistant that works only for them, or their inbox assistant. An agent of your own is a copy of an app's template that works for you alone (Templates and copies). Nobody else may ask it, mention it, give it work or decide its approvals, admins included. You may also make it private: then nobody else in the product sees its conversations, its instructions or its data, admins included.
This page covers My agents, asking for your own agent, what an agent of
your own answers, what private stops and what it does not, what admins and
managers see, and what happens when someone leaves. It describes the
golive branch. What is not possible yet is listed at the
end.
Private agents are available from the release that brought storage version 5; operators see Operations.
My agents#
My agents in the sidebar (/agents), "The agents that work for you",
has three tabs.
Yours groups the agents that work for you:
| Group | What is in it |
|---|---|
| A notice at the top | "Eli Novak made Sales Assistant for you", with Turn it on and Not for me |
| Your own | Your own agents; a private one carries a Private capsule |
| Your team's | Shared agents of your team that work for you |
| Company | The other shared agents that work for you |
| Archived | Your own agents archived in the last 90 days, with Restore |
Each row has its one line, what runs for you on it ("Weekdays: Your follow-ups today at 09:07", see Team schedules), "Offered to you" for an agent that works for you once you turn it on, and "Updated 9 Oct by Eli Novak: new steps for demo requests" after a change. Ask opens a conversation with it; an offered one shows Turn on and Not for me instead. Its menu has Make my own version, Turn off for me (unless an admin made it required for you), and What it can do, the agent's page as you see it: who manages it, what it can use, and Turn on or Turn off for me. For your own agents the menu adds Settings, Pause or Resume, Download its data and Archive.
With nothing there: "No agents work for you yet. Get one." The My agents row in the sidebar carries a small dot when something waits for you there. Holders and admins see Agents I manage → at the top, to Apps > Agents.
Get an agent lists what you may have your own version of: templates open to personal copies (the Inbox Assistant first, while the Inbox app is enabled) and shared copies that work for you whose managers allow it. Each row says "Your own Inbound Sales Assistant", who decides ("Sam Ortiz or Eli Novak decides", or "made at once"), and Make my own or Ask for my own.
Requests lists your requests with their state (Waiting, Approved, Rejected, Withdrawn) and Withdraw on a waiting one. For holders it first lists "Waiting for you", with Approve and Reject.
Asking for your own agent#
A template is open to people's own copies when its app says so (the Inbox Assistant, and Sales Assistant from CRM version 2) or an admin turned on People may ask for their own on the app's Templates tab. A shared copy is open when its managers turned on People it works for may ask for their own in its settings.
- On Get an agent, choose Ask for my own (or Make my own), or Make my own version in an agent's menu.
- The sheet, "Your own Inbound Sales Assistant", has:
- Name, "Alice's Inbound Sales Assistant" to start with.
- Start from: the copy as it is now, or its template.
- What it will use: its tools in words. A tool that reaches data you do not already reach says "an admin approves this one".
- Private, with what it means (below).
- Replaces Inbound Sales Assistant for you, on when you start from a copy you use: "Its approval rules come with it."
- A note to whoever decides, and at the foot who decides.
- Choose Ask (or Make it when it is made at once).
Every holder covering you gets the request, never you; see Manage agents. The company makes the Inbox Assistant at once for everyone; other templates wait for a decision. When it is approved, the agent is yours: it is under Your own, acting for you.
Refusals:
| When | You read |
|---|---|
| The template is not open to people's own copies | "Sales Assistant is not open to personal agents; ask an admin" |
| Its app is not bound to any of your teams and no copy of it works for you | "The Sales app is not set up for your team; ask an admin" |
| A request for it already waits | "Your request for your own Inbound Sales Assistant is still waiting; withdraw it first" (409 request_open) |
| You have as many as the company allows (5 by default) | "You have 5 of your own agents, the most your company allows (5)" |
| The company does not offer them | "Your company does not offer personal agents; ask an admin" |
| More than 10 requests in a day | "at most 10 requests a day" |
Replaces. Your own copy may replace a shared copy you use. The shared one then stops working for you, its team schedules run for you on your own copy instead, and your own copy carries its approval rules, which you cannot remove. Turning Replaces off, or archiving your own copy, gives you the shared one back. When the shared copy is archived, your Replaces lapses and you are told; your own copy keeps working.
Made for you. A holder may make an agent for you alone. It is made off and acts for nobody until you choose Turn it on; Not for me archives it and its maker is told. After 14 days without an answer it is archived.
Try it: Eli makes one for Alice#
- As ada, grant Eli manage agents for Sales (Manage agents).
- As eli, on CRM's Templates tab choose Make a copy on Sales
Assistant. Name it
Alice's Sales Assistant, choose People under Who it works for, find Alice Chen. The note reads "This makes a personal copy for Alice Chen. Alice turns it on, and may make it private." Choose Make the copy: "Made Alice's Sales Assistant for Alice Chen: waiting for them to turn it on". - As alice, My agents reads "Eli Novak made Alice's Sales Assistant for you". Choose Turn it on. It moves under Your own.
- As ada, start a new conversation and open the agent picker: it does not offer Alice's agent. Asking it through the API answers 404 "No agent here by that name". As sam, who leads Sales, its page reads the same.
An agent of your own answers you only#
A personal agent answers its owner and nobody else, admins included. Every
refusal is the same 404, "No agent here by that name", so no answer tells
anyone that it exists, what it is called or whose it is. Its id is opaque
(pc- and ten letters), and its name is unique only among its owner's own.
| Path | What happens for anyone but its owner |
|---|---|
| Asking it, in the composer or the API, alone or with other agents | Not offered; 404 |
| Mentioning it in a thread | Nothing wakes; the text stays text |
| Consulting it from another agent, giving it a task, a repeat, a group or a team schedule | 404 |
| An outside agent handing it work | Refused |
| Making a copy from it | Only its owner |
| Its approvals, drafts, questions and escalations | Its owner only (below) |
| A shared agent asked "show me Alice's pipeline" | Acts for the asker, capped at what the asker may read |
| Changing it | Anyone else's change, its model and required parts included, waits for the owner's OK showing the exact change |
Private#
Private is the owner's choice on an agent of their own, in Settings (Private) or when asking for it. It is off by default, and on by default for the Inbox Assistant. Only the owner turns it on or off: the switch acts like a password, so it needs a sign-in within the last ten minutes. If yours is older, Confirm it is you asks for your password first, and an API token can never change it. Restoring an older version of the agent's settings that turns private on or off asks the same. You get an email each time it changes. Under every Private switch the product says plainly what it does and does not stop:
Only you will see its conversations and instructions. Admins see that it exists and what it costs, and can pause or archive it. Whoever runs the server can read everything outside the app. What it changes in company records stays visible as usual.
Who sees what#
| What | The owner | Admins | Holders covering the owner | Anyone else, team leads included |
|---|---|---|---|---|
| That it exists: template, owner, state, since when | Yes | Yes | Yes | No |
| Its name and one line | Yes | "Private copy of Sales Assistant" | No | No |
| Its settings: tools, model, limits, schedules, rules | Yes | Yes | No | No |
| This month's cost | Yes | Yes | Yes | No |
| This month's runs, failures, approvals waiting, refusals, as counts | Yes | Yes | No | No |
| Its instructions, checks, proposed changes, history | Yes | No | No | No |
| Its conversations, runs, answers, files, memory | Yes | No | No | No |
| Its approvals and questions | Yes, and only the owner decides them | Counts only | No | No |
| Live activity | In words | "At work", no words | No | No |
| The event log | Content-free for everyone: ids, costs, times and fixed codes | The same | No | No |
| Search | In the owner's own searches | Not found | No | No |
| An inbox assistant's messages, rules, notes and drafts | Yes | No | No | No |
| Replies an inbox assistant sent | In full, with Download | Daily counts by channel and how sent | No | No |
Nobody can open a private agent, for any reason. There is no break-glass for an investigation or a legal hold (the user's decision of 8 October 2026), and the admin help on the governance view says so: "Private agents cannot be opened by anyone but their owner, for any reason; the company's own mail and chat systems keep what was sent."
Private is a boundary in the product, not encryption: whoever runs the server and holds the state file, or holds a backup and its recovery key, can read everything outside the product.
Only in your own conversations#
A private agent works only in its owner's own conversations: a one-to-one chat with it, or a thread with no other person in it. Asking it anywhere else is refused before anything runs: "Your private agent works only in your own conversations". Adding a person to a thread it is in is refused too. You may add shared agents to a private conversation; their work there is private as well.
A conversation made with a private agent stays private after you turn private off. Turning private on applies to conversations made from then on.
Privacy follows the conversation#
Everything that runs in a private conversation, or in work started from one, is private, whichever agent runs it: a shared agent your private one hands a task to, an agent it consults, the members of an ask to several agents. Others see such runs only as state and cost ("At work").
- Memory. What runs in private scope decides or remembers goes to your own memory, whatever the plan asked for, and never to a review queue for the team or the company.
- Company records. What your private agent changes in company data (a lead's stage) stays company data, visible as usual. Its history reads "by Alice Chen's private agent", with no link to the run; opening the run by id is 404.
The event log#
The log is hash-chained, so nothing written to it can be removed. Events in private scope are therefore written without content: a task's title reads "Private task", a step reads "step 3: query", a post or a note has no text, and reasons are fixed codes. Your own views read your runs, threads and steps themselves, in full. See Events and the audit log.
Its approvals and questions#
An agent of your own reports to you. Its approvals, drafts, questions and escalations go to you: no lead and no admin decides them in your place.
- Only you approve or edit them. Others may only reject one, with a reason you read, and only when the agent is not private. On a private agent they see nothing of it; their brake is Pause.
- Company rules always win. A rule that sends one of its steps to someone
else (say, payments over $500 need finance, or "their manager") is
decided by the people it names, never by you in their place:
- On a private agent you are asked first: "This step will be shown to Fiona Reyes (company rule: payments over $500 need finance). Show it?", with the call's arguments. On Show, Fiona sees the tool and its arguments only, and decides; your run reads "Waiting for Fiona Reyes". On Don't, the step is refused with the rule's name.
- On an agent that is not private, the step goes straight to Fiona.
- Either way you may reject it, but approving it is Fiona's: "a rule sends this to Fiona Reyes to approve; you may reject it".
- A rule that denies still denies.
- A task in private scope that runs past its due time is not handed to anyone; you are reminded instead.
- A question from a private agent is never passed on or escalated, and nobody else can answer it (404); when its time runs out only Assume and Stop apply.
The same holds for a reply through a tool that sends a message in your name (the inbox assistant's replies): only you approve or edit it, whichever agent calls it. When a company rule sends such a message to someone else for approval, they approve it first and you sign it after them; it goes out only when both of you have.
What admins and managers see#
On Apps > Agents and the agent's page, someone else's private agent shows the governance view under a banner: "Private: only Alice Chen sees its conversations."
- Admins: owner, made from ("Sales Assistant v1"), state, who made it, this month's cost, its settings, and this month's runs, failures, approvals waiting and refusals. For an inbox assistant, Sent for Alice: replies by day, channel and how sent, with money, legal, HR and personal mail together as "Other, private" (The inbox assistant). Actions: Pause (with a reason the owner reads), Set a limit, Archive (with a reason). There is no Open, Ask or Export.
- Holders covering the owner: owner, made from, state, since when and this month's cost; nothing else.
- Anyone else, team leads included: nothing. "No agent here by that name."
Apps > Agents folds people's own agents into one row a template ("Sales Assistant · 2 personal copies"), searched by owner. Spending reports count a private agent as "Private copy of Sales Assistant (Alice Chen)".
Admins keep their brakes: Pause (a switch only an admin lifts), a limit, Archive with a reason, Pause every copy of a template, and the global switch. They cannot open it, ask it, export it, or change its behaviour or model.
Spending#
| Limit | Default |
|---|---|
| Each of your own agents, a month | The template's (the Inbox Assistant: $10), else $5 |
| All your own agents together, a month | $20 |
| The company's own agents together, a month | $500 |
At a limit the agents stop until the month turns, and you are told at 80% and at 100%. A personal agent's run charges no team's budget. See Team schedules for how monthly limits work.
When people leave or change#
| When | What happens to their own agents |
|---|---|
| They leave a team | Their own agents stay; a Replaces of a copy they no longer use lapses |
| They are deactivated | Paused |
| They are offboarded | Archived; their delegations revoked; open drafts and approvals expire; a reply held in its undo window is dropped, not sent; channel accounts and personal connections revoked. Private content stays unreadable to everyone and is purged after the company's retention for private content (90 days by default; 0 purges it at once), or the sent records' retention when that is shorter. Event metadata stays |
| Their email address changes | Their inbox channel accounts pause until they connect again, and the old address is told |
People who own a private agent are protected around the product too: a password reset link for them is only ever mailed to their own address, never shown to the admin who asked for it; they are told when an admin changes where backups go or fetches the recovery key.
Your own download. Download its data on My agents (and Download my assistant's data on the inbox assistant's Settings) gives you a file of your agent's conversations, drafts, rules, notes and sent records. Nobody else can download it, admins included. Like the Private switch, it needs a sign-in within the last ten minutes, and you get an email each time.
Erasure by address or number. When someone outside the company asks it
to erase what it holds about them, an admin holding the data_owner role
uses POST /api/governance/erase { identifier }: messages and sent records
from and to that address or number are deleted in every person's store.
The admin sees only how many rows from how many people, each owner reads
"A message from a sender was erased at the company's request", and the log
records the counts, never the identifier.
Not possible yet#
- Erasure by address or number on the screen (Governance); the API only.
- Changing the company's limits for people's own agents (how many each, the monthly caps, retention, which are made at once) on the screen or through the API.
- Deleting a private agent's conversations before the retention runs out.
- Opening a private agent's conversations for an investigation: not planned.
For developers#
API#
All under /api.
| Method and path | Who | Purpose |
|---|---|---|
GET /me/agent-requests |
Anyone | { mine, waiting_for_me } |
POST /me/agent-requests/check |
Anyone | { from, name, private, replaces, note }: what a request would do (its tools in words, who decides), filed nowhere |
POST /me/agent-requests |
Anyone | The same body: 201 { outcome: "made", copy } when made at once, 202 { outcome: "requested", approval } otherwise |
DELETE /me/agent-requests/:id |
The person who asked | Withdraw |
POST /copies/:id/accept |
The person it was made for | { on } |
GET /me/copies/:id/export |
Its owner, signed in within ten minutes | Download its data; 403 reauth_required for an older sign-in, session_required for a token; 404 for anyone else |
PATCH /copies/:id |
Its owner | { patch: { private, replaces, … }, version }; a patch that sets private needs a session signed in within ten minutes (403 reauth_required, or session_required for a token) |
POST /copies/:id/history/restore |
Its managers or owner | { kind: "settings", version }: a version whose private or replaces differs from now needs the same recent sign-in |
POST /governance/erase |
An admin holding data_owner |
{ identifier }: counts only; 20 a day |
GET /copies/:id answers an admin the governance form and a covering
holder the short form for someone else's private agent; anyone else 404.