Skip to main content
Settings → Organization → Groups and Tool policies. Visible to admins and owners, when groups and tool policies are enabled for your organization.

Groups

Groups let you share agents, prompts and skills, and manage connector access, for a whole team at once instead of person by person.
1

Open Groups

Go to Settings → Organization → Groups.
2

Create a group

Click Create group, give it a Group name and an optional Description, then Select members.
3

Use it

Search groups from the search box. Edit a group to rename it, change its description or update its members; Delete group removes it (this cannot be undone).
Once a group exists, any user can pick it as a sharing target — for example when sharing an agent, choose the group instead of adding people one by one.

Tool policies (connector access)

Tool policies control which users and groups can use each connector (MCP server). A denied user or group can never use the connector; when you allow specific users or groups for a connector, only they can use it. Open Settings → Organization → Tool policies. Three views are available:
Select a connector to see and manage who can use it. Each connector shows a status: Open (everyone in the organization), Restricted (only listed users/groups), Exceptions (everyone except listed users/groups), or Blocked (no one).Use Add a rule to allow or deny a user or group, or Deny for everyone in the organization to block it outright.
Admins of your own organization are never affected by its tool policies; admins of other organizations are.
Start with sensitive connectors (CRM, email, finance tools): restrict them to the specific group that needs them, and leave low-risk connectors open to everyone.