From what I gather, the agent doesn't seem fully assertive, since even when the instructions are changed, it can still pull in information beyond the specified data source. While it does check user permissions, the issue is that the agent can still share text-based information even when the user isn’t allowed to access the original content. The user just can't open the actual page, but they still receive details from it — which defeats the purpose if we want to enforce strict access controls.
During my tests, I also noticed that users can get information from restricted Confluence spaces by simply asking other Rovo agents in the company, even if they don’t have access to that space themselves.
Another point is that there doesn't seem to be any restriction on who can access the agents themselves — it looks like everyone in the company can find and use any agent that’s been created.
Is there any official place where we can suggest improvements or share feedback?
Right now, the agent’s behavior makes it hard to justify using it with a knowledge base if it doesn’t strictly respect the data boundaries — or if it exposes info to users who shouldn't have access to the source.