Govern
Governance in Studio is not a single switch. It is five separate surfaces, each answering a different question.
| Page | Answers |
|---|---|
| Guardrails | What must never go in or come out of an agent? |
| Audit logs | Who changed what, and who was refused? |
| Audit traces | What exactly happened inside a run? |
| Usage | How much are we spending, and on what? |
| RBAC, teams and permissions | Who in the company can do which of the above? |
The two-layer model
Studio checks access twice, and the two checks answer different questions.
Loading diagram...
| Layer | Granted by | Example |
|---|---|---|
| Role (RBAC) | An admin, in Settings → Roles | "Members may create agents." |
| Object permission (sharing) | Whoever admins that object | "Priya is an Editor on the Support Triage agent." |
