---
title: "Organization policy controls"
canonical: "https://canmyagentuse.com/features/admin-policy-controls"
contentKind: "feature"
locale: "en"
description: "Centrally enable, disable, constrain, and enforce models, tools, data paths, sharing, and agent behavior."
llmSummary: "Organization policy controls are centrally enforced product settings; user preferences and prompt instructions are not organization policy."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["security","governance","policy","enterprise"]
---

# Organization policy controls

Organization policy controls are centrally enforced product settings; user preferences and prompt instructions are not organization policy.

- HTML: https://canmyagentuse.com/features/admin-policy-controls
- JSON: https://canmyagentuse.com/api/v1/features/admin-policy-controls.json
- Markdown: https://canmyagentuse.com/features/admin-policy-controls.md

Terminology basis: **Common product term** — https://docs.x.ai/grok-bot/teams-and-enterprises.

## Current support at a glance

Organization policy controls: 1 supported, 3 partial, 0 unsupported, 27 unreviewed across 31 cataloged products.

- Reviewed current products: 4 of 31
- Supported: 1
- Partial: 3
- Unsupported: 0
- Unreviewed: 27
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

This row covers centrally enforced organization policy, not a user preference or a natural-language instruction the agent may ignore. Useful controls cover allowed models and providers, tools and connectors, MCP servers, network destinations, data sharing, uploads, memory, retention, training use, public links, autonomous actions, and sub-agent fan-out.

Evidence should record scope, role required to change policy, inheritance and exceptions, client support, propagation time, offline behavior, precedence over local configuration, change logs, and the user experience when policy blocks an action.

## Catalog context

- Category: [security-privacy](/categories/security-privacy.md)
- Terminology basis: Common product term
- Aliases: enterprise policy, organization controls, managed settings
- Family: [Security and privacy](/features/data-security-controls.md)
- Siblings: [Audit logs](/features/audit-logs.md), [Data residency](/features/data-residency.md), [Data retention controls](/features/data-retention-controls.md), [Encryption key management](/features/encryption-key-controls.md), [Offline operation](/features/local-only-mode.md), [Secrets management](/features/secrets-management.md), [Training data controls](/features/training-data-controls.md)

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Grok Bot team documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): enterprise availability is rolling out and controls vary by organization plan
  - Constraint (policy): documented controls cover cloud agents, privacy mode, MCP and plugins, team rules, network allowlists, and local execution; full model, upload, sharing, retention, and subagent fan-out policy is not established
  - Evidence: [xAI — Grok Bot for teams and enterprises](https://docs.x.ai/grok-bot/teams-and-enterprises) — documented; observed 2026-08-28
  - Qualification note 1: Evidence checked 2026-08-28: Grok Bot team administrators can control Cloud Agents, inherit team privacy mode, MCP configuration and team rules, enforce MCP server and network allowlists, restrict member-added servers, and restrict local-computer execution. The reviewed docs do not establish the full policy surface in this row.

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 ChatGPT Enterprise managed configuration observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (policy): managed requirements and defaults can constrain permission profiles, approvals, sandboxing, filesystem and network access, browser and computer use, apps, plugins, MCP servers, feature flags, and telemetry
  - Constraint (runtime): support is key- and client-version-specific; managed source precedence, signed cache behavior, startup refresh, and fail-closed loading are documented boundaries
  - Constraint (policy): the reviewed page does not establish every upload, retention, sharing, model, or subagent-fan-out control in this row
  - Evidence: [OpenAI — Managed configuration](https://learn.chatgpt.com/docs/enterprise/managed-configuration) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: ChatGPT Enterprise managed configuration can enforce requirements and defaults across supported local clients, including approval and permission profiles, sandbox modes, filesystem and network rules, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry. Version support and source precedence are material boundaries.
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Unknown**
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Unknown**
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Unknown**
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Unknown**
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Unknown**
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Claude Code managed settings observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (policy): admin settings override user, project, local, and --settings values and can govern permissions, models, MCP servers, marketplaces, sandboxing, login, telemetry, and minimum versions
  - Constraint (transport): policy can be delivered by server-managed settings, MDM or OS policy, managed files, or a restricted Windows user-policy fallback
  - Constraint (runtime): source selection and optional merging have documented precedence, version gates, stricter-lower-level exceptions, refresh intervals, and /status verification
  - Evidence: [Anthropic — Deploy Claude Code managed settings](https://code.claude.com/docs/en/managed-settings) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Claude Code managed settings override user, project, local, and command-provided settings, can be delivered from the claude.ai admin console, MDM, OS policy, or managed files, and cover permissions, models, MCP, marketplaces, sandbox restrictions, login, and telemetry. Some stricter lower-level settings and source-composition rules remain exceptions.
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Partial**
  - Target: hosted-observation — 2026-08-28 Codex managed configuration observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (policy): requirements.toml and managed defaults can centrally constrain permissions, approvals, sandboxing, filesystem and network access, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry
  - Constraint (runtime): supported keys depend on Codex version and authentication; cloud-managed bundles are identity-matched, signed, cached, and fail closed when no valid cache can be loaded
  - Constraint (policy): API-key-only authentication and Platform organization controls are outside this ChatGPT workspace configuration cell
  - Evidence: [OpenAI — Managed configuration](https://learn.chatgpt.com/docs/enterprise/managed-configuration) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: ChatGPT Enterprise managed configuration can enforce requirements and defaults across supported local clients, including approval and permission profiles, sandbox modes, filesystem and network rules, web and computer use, apps, plugins, MCP servers, feature flags, and telemetry. Version support and source precedence are material boundaries.
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
