Skip to main content

Admin controls

Tenant admins decide who can share and who can clone in the Internal Marketplace. Per-project toggles let project admins narrow it further.

Where the controls live

  • Tenant level: Settings → Marketplace & Sharing.
  • Project level: Project Settings → Marketplace.

Tenant-level controls

Who can share

  • Admin Only (default for tighter governance) — only tenant admins can publish.
  • All Members — every Builder-role-or-higher member can publish.
  • Specific Roles — pick a subset of roles allowed to publish.

Who can clone

  • All Members (default) — every tenant member can clone.
  • Disabled — clone is turned off tenant-wide.
  • Specific Roles — pick a subset of roles allowed to clone.

Sharing scope

  • Locked to Internal in M1. Public sharing across tenants is on the roadmap for a future milestone.

Project-level controls

Each project has its own toggles in Project Settings → Marketplace:

  • Sharing enabled — on/off for this project.
  • Cloning enabled — on/off for this project.

The project-level toggles are subordinate to the tenant-level setting — if tenant allows but project disables, the project setting wins.

Admin removal of listings

A tenant admin can remove any listing from the Marketplace at any time. Removal:

  • Hides the listing from browse and search.
  • Does not affect existing clones — Cloners retain their copy.
  • Preserves analytics — the Builder's analytics for the removed listing remain accessible.
  • Generates an audit log entry: "Listing removed by admin" with the actor, target, and timestamp.

(An open question being tracked is whether the admin should document a reason at removal time for accountability. Not enforced today.)

Audit visibility

  • Tenant admins can view the full audit log for all listings in the tenant.
  • Project admins can view logs scoped to their project.
  • Builders can view logs for their own listings only.
  • Individual Cloner PII (name or email) is not surfaced to Builders in audit views — only aggregate clone counts and org names.

The audit log is read-only and cannot be edited or deleted by anyone, including tenant admins. Minimum retention is 12 months, with CSV export available to tenant admins. See Audit log for the broader audit log mechanics.

Trial credits and policy

The trial-credit allowance per Cloner per agent and any sandbox time limits are set by the Finance + Product team; they may change over time. Check your current workspace settings or contact support for the active policy.