How org/workspace structure relates to agent identity and permission policies
Org and workspace structure (this site) governs human administrative access to Console resources — who can create keys, see billing, manage workspaces. It is a separate layer from agent IDENTITY/attribution (which surface an agent acts under, service-account vs. personal-account — see subagentidentities.com) and from agent TOOLSET permission policies (which tools an agent may call and under what default posture — see subagentpermissions.com). An org can contain many workspaces, each of which may host agents running under distinct identities and permission policies.
See subagentidentities.com for agent identity/attribution, and subagentpermissions.com for agent toolset permission policies — this site intentionally does not duplicate either.
General, well-established Anthropic Console concept combined with this repo's own already-documented Identity and Permission Policy primitives.
created 2026-07-02 08:27:28 · JSON