NebulaNebula
Getting Started

Sharing & access

Share agents, jobs, and miniapps with your workspace and control who can view or edit each one — plus how a shared agent runs on its owner's connections.

You can share any agent, job, or miniapp with your workspace and set exactly who gets to open it and who gets to change it — all from one Access dialog. Connections stay personal, so a shared agent always acts through its owner's connected apps.

Every agent, job, and miniapp has an Access row with a Manage button (you'll see View instead if you only have view access). Open it to set two things: the general access level for the whole workspace, and named people with their own view-or-edit grant.

Set general access

General access decides what everyone in the workspace can do with the item, before you grant anyone individual access.

RestrictedWorkspace · can viewWorkspace · can edit
Who can open itOnly people you addEveryone in the workspaceEveryone in the workspace
What they can doDepends on their grantView and use itEdit it
Best forPersonal or sensitive workTeam workers everyone relies onShared building blocks the team maintains together

You pick a general access level when you create an agent, job, or miniapp, and you can change it anytime from the Access dialog.

Grant specific people

Below general access is a people list. Add a teammate and choose their level — the same two levels apply whether the item is Restricted or open to the whole workspace.

Can open and use the item — chat with the agent, run the job, launch the miniapp — but can't change how it's built or who else has access.

Can do everything a viewer can, plus edit the item, delete it, and manage its access.

The person who created an item is always an Editor and can't be removed — someone always owns it. A member's effective access is the higher of the general access level and any grant you give them by name.

Your connections belong to you

When you connect an app — Gmail, Slack, GitHub, and so on — that connection is tied to your account, not to the workspace as a whole.

On the Settings → Tools → Accounts tab you only ever see the connections you set up. You won't see a teammate's connected accounts, and they won't see yours.

Connecting an app authorizes Nebula to act as you in that app. That's why connections stay personal — each person grants their own access.

What happens when you share an agent

Here's the part that surprises people: a shared agent always runs with its owner's connections, no matter who starts it.

You build an agent, connect your Gmail to it, and give it workspace access.
A teammate opens the agent and asks it to send an email.
The agent sends that email through your Gmail connection — because the connection belongs to you, the owner.

So sharing an agent shares the capability, and the work flows through the owner's connected accounts. Keep an agent restricted if you'd rather its access stay with you alone.

Two people, two Gmails

Because connections are personal, two teammates connecting the same app create two separate connections — and effectively two separate agents.

Not sure who can see what? Ask Nebula in chat — it can tell you an item's access and which connections an agent uses. For anything unresolved, email support@nebula.gg. See Support for more options.

On this page