Skip to content

Governance

Every script has an owner: whoever created it. Its owner, or a workspace owner or admin, controls three things on its page, under Settings.

  • Everyone in the workspace, the default.
  • Only these teams, chosen from the workspace’s teams (Settings → Members). Members outside them don’t see the script at all: not in the app, the API, as an agent’s tool, or in its runs. Workspace owners and admins always see everything.

Guests see only what’s shared with a team they’re in.

Through the API: PATCH /v1/scripts/{slug} with { "access": "teams", "teamIds": ["…"] } or { "access": "workspace" }.

Policy What waits for a person
No approval (the default) Nothing. Runs start right away.
Agents need approval Runs started by an AI agent (through the MCP server).
Every run needs approval (Business) Every run, except by workspace owners and admins.

A held run shows as Awaiting approval. Reminix notifies workspace owners and admins, and they decide on its approval page. If it’s approved, it runs the version it was asked for, with its inputs. If it’s denied, or not decided within a day, it’s Cancelled. Through the API, a held run answers 202 with the run and the request’s approveUrl; read the run (GET /v1/runs/{id}) to see how it ended. An agent’s tool says it’s waiting, with the link.

The policy is a setting of the script, never part of its code, so publishing new code can’t loosen it. If a workspace moves to a plan without every-run approval, a script that has it keeps it.

The script’s owner, or a workspace owner or admin, publishes a version. Two cases need a person’s approval instead:

  • An AI agent’s publish, always. The request appears for a workspace owner or admin to approve.
  • Everyone’s publish, when the workspace turns on Settings → Scripts → Publishing → “Publishing needs a second person” (Business). The publish becomes a request that another owner or admin approves, not the person who asked. If the person who asked approves it themselves, it’s refused; ask again for someone else.

Every change of access, policy and setting, and every approval, is in the workspace’s audit log.