Sharing & access
Share agents, jobs, and miniapps with your workspace and control who can view or edit each one — plus how a shared agent runs on its owner's connections.
You can share any agent, job, or miniapp with your workspace and set exactly who gets to open it and who gets to change it — all from one Access dialog. Connections stay personal, so a shared agent always acts through its owner's connected apps.
Every agent, job, and miniapp has an Access row with a Manage button (you'll see View instead if you only have view access). Open it to set two things: the general access level for the whole workspace, and named people with their own view-or-edit grant.
Set general access
General access decides what everyone in the workspace can do with the item, before you grant anyone individual access.
| Restricted | Workspace · can view | Workspace · can edit | |
|---|---|---|---|
| Who can open it | Only people you add | Everyone in the workspace | Everyone in the workspace |
| What they can do | Depends on their grant | View and use it | Edit it |
| Best for | Personal or sensitive work | Team workers everyone relies on | Shared building blocks the team maintains together |
You pick a general access level when you create an agent, job, or miniapp, and you can change it anytime from the Access dialog.
Grant specific people
Below general access is a people list. Add a teammate and choose their level — the same two levels apply whether the item is Restricted or open to the whole workspace.
Can open and use the item — chat with the agent, run the job, launch the miniapp — but can't change how it's built or who else has access.
Can do everything a viewer can, plus edit the item, delete it, and manage its access.
The person who created an item is always an Editor and can't be removed — someone always owns it. A member's effective access is the higher of the general access level and any grant you give them by name.
Your connections belong to you
When you connect an app — Gmail, Slack, GitHub, and so on — that connection is tied to your account, not to the workspace as a whole.
On the Settings → Tools → Accounts tab you only ever see the connections you set up. You won't see a teammate's connected accounts, and they won't see yours.
Connecting an app authorizes Nebula to act as you in that app. That's why connections stay personal — each person grants their own access.
What happens when you share an agent
Here's the part that surprises people: a shared agent always runs with its owner's connections, no matter who starts it.
So sharing an agent shares the capability, and the work flows through the owner's connected accounts. Keep an agent restricted if you'd rather its access stay with you alone.
Two people, two Gmails
Because connections are personal, two teammates connecting the same app create two separate connections — and effectively two separate agents.
Not sure who can see what? Ask Nebula in chat — it can tell you an item's access and which connections an agent uses. For anything unresolved, email support@nebula.gg. See Support for more options.
Related
Quickstart
Sign up for Nebula, meet your workspace, and create your first AI agent, channel, or miniapp — all in under five minutes, no setup required.
Your first agent
Create your first Nebula agent — a focused AI worker for one job. A five-step wizard covers identity, description, tools, access, and review.