Product feature · security-privacy

Organization policy controlsCommon product term

Centrally configure and enforce product settings for an organization.

Terminology basis: Common product term. xAI — Grok Bot for teams and enterprises

Organization policy controls: 1 supported, 3 partial, 0 unsupported, 27 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in Security and privacy7 capabilities

Current evidence by product

Can my agent use Organization policy controls?

Read across for the answer. 4 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported1
  • Partial3
  • Unsupported0
  • Unknown27
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

This row covers centrally enforced organization policy, not a user preference or a natural-language instruction the agent may ignore. Useful controls cover allowed models and providers, tools and connectors, MCP servers, network destinations, data sharing, uploads, memory, retention, training use, public links, autonomous actions, and sub-agent fan-out.

Evidence should record scope, role required to change policy, inheritance and exceptions, client support, propagation time, offline behavior, precedence over local configuration, change logs, and the user experience when policy blocks an action.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Grok Botdesktop · current
Partial
Target
2026-08-28 Grok Bot team documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planenterprise availability is rolling out and controls vary by organization plan
  • policydocumented controls cover cloud agents, privacy mode, MCP and plugins, team rules, network allowlists, and local execution; full model, upload, sharing, retention, and subagent fan-out policy is not established
Evidence
ChatGPTdesktop · current
Partial
Target
2026-08-28 ChatGPT Enterprise managed configuration observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • policymanaged requirements and defaults can constrain permission profiles, approvals, sandboxing, filesystem and network access, browser and computer use, apps, plugins, MCP servers, feature flags, and telemetry
  • runtimesupport is key- and client-version-specific; managed source precedence, signed cache behavior, startup refresh, and fail-closed loading are documented boundaries
  • policythe reviewed page does not establish every upload, retention, sharing, model, or subagent-fan-out control in this row
Evidence
Codex CLIcli · current
Partial
Target
2026-08-28 Codex managed configuration observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • policyrequirements.toml and managed defaults can centrally constrain permissions, approvals, sandboxing, filesystem and network access, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry
  • runtimesupported keys depend on Codex version and authentication; cloud-managed bundles are identity-matched, signed, cached, and fail closed when no valid cache can be loaded
  • policyAPI-key-only authentication and Platform organization controls are outside this ChatGPT workspace configuration cell
Evidence
Claude CLIcli · current
Supported
Target
2026-08-28 Claude Code managed settings observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • policyadmin settings override user, project, local, and --settings values and can govern permissions, models, MCP servers, marketplaces, sandboxing, login, telemetry, and minimum versions
  • transportpolicy can be delivered by server-managed settings, MDM or OS policy, managed files, or a restricted Windows user-policy fallback
  • runtimesource selection and optional merging have documented precedence, version gates, stricter-lower-level exceptions, refresh intervals, and /status verification
Evidence
  1. 1. Evidence checked 2026-08-28: Grok Bot team administrators can control Cloud Agents, inherit team privacy mode, MCP configuration and team rules, enforce MCP server and network allowlists, restrict member-added servers, and restrict local-computer execution. The reviewed docs do not establish the full policy surface in this row.
  2. 2. Evidence checked 2026-08-28: ChatGPT Enterprise managed configuration can enforce requirements and defaults across supported local clients, including approval and permission profiles, sandbox modes, filesystem and network rules, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry. Version support and source precedence are material boundaries.
  3. 3. Evidence checked 2026-08-28: Claude Code managed settings override user, project, local, and command-provided settings, can be delivered from the claude.ai admin console, MDM, OS policy, or managed files, and cover permissions, models, MCP, marketplaces, sandbox restrictions, login, and telemetry. Some stricter lower-level settings and source-composition rules remain exceptions.