{
  "title": "Organization policy controls",
  "description": "Centrally enable, disable, constrain, and enforce models, tools, data paths, sharing, and agent behavior.",
  "slug": "admin-policy-controls",
  "locale": "en",
  "seoTitle": "Organization policy controls compatibility — Can My Agent Use",
  "socialTitle": "Organization policy controls",
  "socialDescription": "Compare organization-wide enforcement for models, tools, connectors, sharing, data, and autonomous actions.",
  "llmSummary": "Organization policy controls are centrally enforced product settings; user preferences and prompt instructions are not organization policy.",
  "audience": "Enterprise administrators, security teams, and platform owners.",
  "contentKind": "feature",
  "status": "published",
  "tags": [
    "security",
    "governance",
    "policy",
    "enterprise"
  ],
  "updated": "2026-08-28T00:00:00.000Z",
  "published": "2026-08-28T00:00:00.000Z",
  "category": "security-privacy",
  "summary": "Centrally configure and enforce product settings for an organization.",
  "specLabel": "Common product term",
  "aliases": [
    "enterprise policy",
    "organization controls",
    "managed settings"
  ],
  "capabilityKind": "atomic",
  "parent": "data-security-controls",
  "related": [
    "audit-logs",
    "training-data-controls",
    "human-approval"
  ],
  "relations": [],
  "highlight": false,
  "notes": [
    {
      "id": 1,
      "text": "Evidence checked 2026-08-28: Grok Bot team administrators can control Cloud Agents, inherit team privacy mode, MCP configuration and team rules, enforce MCP server and network allowlists, restrict member-added servers, and restrict local-computer execution. The reviewed docs do not establish the full policy surface in this row."
    },
    {
      "id": 2,
      "text": "Evidence checked 2026-08-28: ChatGPT Enterprise managed configuration can enforce requirements and defaults across supported local clients, including approval and permission profiles, sandbox modes, filesystem and network rules, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry. Version support and source precedence are material boundaries."
    },
    {
      "id": 3,
      "text": "Evidence checked 2026-08-28: Claude Code managed settings override user, project, local, and command-provided settings, can be delivered from the claude.ai admin console, MDM, OS policy, or managed files, and cover permissions, models, MCP, marketplaces, sandbox restrictions, login, and telemetry. Some stricter lower-level settings and source-composition rules remain exceptions."
    }
  ],
  "issues": [],
  "resources": [
    {
      "title": "Methodology",
      "href": "/methodology",
      "kind": "note"
    },
    {
      "id": "xai-grok-bot-team-controls",
      "title": "xAI — Grok Bot for teams and enterprises",
      "href": "https://docs.x.ai/grok-bot/teams-and-enterprises",
      "kind": "docs",
      "publisher": "xAI",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28"
    },
    {
      "id": "openai-managed-configuration",
      "title": "OpenAI — Managed configuration",
      "href": "https://learn.chatgpt.com/docs/enterprise/managed-configuration",
      "kind": "docs",
      "publisher": "OpenAI",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Admin-enforced requirements; cloud-managed requirements; precedence and layering"
    },
    {
      "id": "anthropic-managed-settings",
      "title": "Anthropic — Deploy Claude Code managed settings",
      "href": "https://code.claude.com/docs/en/managed-settings",
      "kind": "docs",
      "publisher": "Anthropic",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Deploy managed settings; surfaces; policy precedence"
    }
  ],
  "support": [
    {
      "harness": "grok-bot-desktop",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            1
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Grok Bot team documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "enterprise availability is rolling out and controls vary by organization plan"
            },
            {
              "type": "policy",
              "value": "documented controls cover cloud agents, privacy mode, MCP and plugins, team rules, network allowlists, and local execution; full model, upload, sharing, retention, and subagent fan-out policy is not established"
            }
          ],
          "evidence": [
            {
              "resourceId": "xai-grok-bot-team-controls",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "chatgpt-desktop",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 ChatGPT Enterprise managed configuration observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "policy",
              "value": "managed requirements and defaults can constrain permission profiles, approvals, sandboxing, filesystem and network access, browser and computer use, apps, plugins, MCP servers, feature flags, and telemetry"
            },
            {
              "type": "runtime",
              "value": "support is key- and client-version-specific; managed source precedence, signed cache behavior, startup refresh, and fail-closed loading are documented boundaries"
            },
            {
              "type": "policy",
              "value": "the reviewed page does not establish every upload, retention, sharing, model, or subagent-fan-out control in this row"
            }
          ],
          "evidence": [
            {
              "resourceId": "openai-managed-configuration",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "codex-cli",
      "versions": [
        {
          "track": "current",
          "status": "partial",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Codex managed configuration observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "policy",
              "value": "requirements.toml and managed defaults can centrally constrain permissions, approvals, sandboxing, filesystem and network access, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry"
            },
            {
              "type": "runtime",
              "value": "supported keys depend on Codex version and authentication; cloud-managed bundles are identity-matched, signed, cached, and fail closed when no valid cache can be loaded"
            },
            {
              "type": "policy",
              "value": "API-key-only authentication and Platform organization controls are outside this ChatGPT workspace configuration cell"
            }
          ],
          "evidence": [
            {
              "resourceId": "openai-managed-configuration",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "claude-cli",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            3
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Claude Code managed settings observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "policy",
              "value": "admin settings override user, project, local, and --settings values and can govern permissions, models, MCP servers, marketplaces, sandboxing, login, telemetry, and minimum versions"
            },
            {
              "type": "transport",
              "value": "policy can be delivered by server-managed settings, MDM or OS policy, managed files, or a restricted Windows user-policy fallback"
            },
            {
              "type": "runtime",
              "value": "source selection and optional merging have documented precedence, version gates, stricter-lower-level exceptions, refresh intervals, and /status verification"
            }
          ],
          "evidence": [
            {
              "resourceId": "anthropic-managed-settings",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    }
  ],
  "html": "/features/admin-policy-controls",
  "markdown": "/features/admin-policy-controls.md",
  "json": "/api/v1/features/admin-policy-controls.json",
  "body": "This row covers centrally enforced organization policy, not a user preference or a natural-language instruction the agent may ignore. Useful controls cover allowed models and providers, tools and connectors, MCP servers, network destinations, data sharing, uploads, memory, retention, training use, public links, autonomous actions, and sub-agent fan-out.\n\nEvidence should record scope, role required to change policy, inheritance and exceptions, client support, propagation time, offline behavior, precedence over local configuration, change logs, and the user experience when policy blocks an action."
}