TalentOS Help
Governance & privacy

What admins can and cannot see

The exact privacy line: admins see what was published and what it cost, never what anyone said, wrote, or asked.

This is the question every team asks before rolling TalentOS out, and it deserves a precise answer rather than a reassuring one.

Visibility is artifact states, never behavior. An admin can see what exists in the workspace and what it cost. An admin cannot see how any individual worked, what they asked, or what their Talent said back. That line is enforced on the server, not in the interface, and it applies to the owner and to managers as well.

Tell your team this before they connect their mail.

What an admin can see

  • Published work. Anything anyone published to the Marketplace, plus department and company memory. It was shared on purpose.
  • The workspace roster. People, roles, departments, pending invitations, and each person's Talent by name with its status.
  • The plan and the pool. Seats, plan, renewal, and the shared credit balance.
  • What work cost. The usage dashboard in Settings shows workspace spend broken down by member and by routine.

What no admin can see

  • Chats. Nobody else reads your conversations with your Talent, in the web console or a connected messaging channel.
  • Personal memory. Your Talent's memory of you is yours. Admins are not an exception to that.
  • Your connected accounts. Connecting email connects it to your Talent, not to the workspace. An admin never reads your mail through TalentOS.
  • What your Talent produced. Private Artifacts and private Routines and Skills stay private until you publish them.
  • Anything a run said. No summary, no error text, no instructions, no context. The usage dashboard is billing information and nothing else.

Spend is the one thing that crosses the line, because someone has to pay the bill. The owner and any admin can see how many credits each member used. They cannot see what those credits were spent doing.

The usage dashboard, precisely

Open Settings and go to usage. Owner and admins see it. Members do not.

For each member it shows how much they used, when, whether runs succeeded, and which model lane ran. For each routine it shows what that routine cost.

Routine names are where this gets subtle, and the product is careful about it. A routine only shows its real name if it was published to the whole workspace. Anyone else's private routine appears as Private routine, with its cost attached. So an admin can see that one member is burning a lot of credits on a private routine and can go and ask them about it, which is the honest amount of information to hand someone who signs the invoice.

Removed members stay in the list, labelled. Their spend was real spend, and dropping them would stop the member column adding up to the workspace total.

Receipts, and who they belong to

Every run leaves one receipt in Activity, inside Settings. Receipts are the canonical record of what happened, and your Activity is your own history, not a feed an admin browses. The bell in the header is a bounded inbox of things needing you right now, such as an approval or a low credit warning. It is not a history and not a management view of anyone else.

A worked example

A marketing admin sees that one member used 1,200 credits on a private Routine this week. The dashboard labels the work Private routine, so the admin can ask about the cost but cannot open the instructions, results, or conversation. If the member publishes the Routine to the Marketplace, its shared name and version become visible to the workspace.

What to check

A member says they can see spend and you did not expect it. They are an admin. Check their role on the Directory tab.

An admin wants a per person report of what was actually done. It does not exist and will not be added by a setting. Ask people to publish the work you want visibility over to the Marketplace, which is the sanctioned path.

A routine you own shows as "Private routine" to your admin. That is correct and expected. Publish it to the workspace if you want it named.

Usage numbers look short. The dashboard reads live over a bounded recent window, and it tells you when a view was truncated rather than quietly showing you less. Narrow the range and read it again.

On this page