Governance
Every script has an owner: whoever created it. Its owner, or a workspace owner or admin, controls three things on its page, under Settings.
Who can use it
Section titled “Who can use it”- Everyone in the workspace, the default.
- Only these teams, chosen from the workspace’s teams (Settings → Members). Members outside them don’t see the script at all: not in the app, the API, as an agent’s tool, or in its runs. Workspace owners and admins always see everything.
Guests see only what’s shared with a team they’re in.
Through the API: PATCH /v1/scripts/{slug} with
{ "access": "teams", "teamIds": ["…"] } or { "access": "workspace" }.
Which runs need approval
Section titled “Which runs need approval”| Policy | What waits for a person |
|---|---|
| No approval (the default) | Nothing. Runs start right away. |
| Agents need approval | Runs started by an AI agent (through the MCP server). |
| Every run needs approval (Business) | Every run, except by workspace owners and admins. |
A held run shows as Awaiting approval. Reminix notifies workspace owners and admins, and they decide on its approval page. If it’s approved, it runs
the version it was asked for, with its inputs. If it’s denied, or not
decided within a day, it’s Cancelled. Through the API, a held run
answers 202 with the run and the request’s approveUrl; read the run
(GET /v1/runs/{id}) to see how it ended. An agent’s tool says it’s
waiting, with the link.
The policy is a setting of the script, never part of its code, so publishing new code can’t loosen it. If a workspace moves to a plan without every-run approval, a script that has it keeps it.
Who publishes
Section titled “Who publishes”The script’s owner, or a workspace owner or admin, publishes a version. Two cases need a person’s approval instead:
- An AI agent’s publish, always. The request appears for a workspace owner or admin to approve.
- Everyone’s publish, when the workspace turns on Settings → Scripts → Publishing → “Publishing needs a second person” (Business). The publish becomes a request that another owner or admin approves, not the person who asked. If the person who asked approves it themselves, it’s refused; ask again for someone else.
Every change of access, policy and setting, and every approval, is in the workspace’s audit log.