Problem:
Currently, when a Rovo agent is set to "Open to all users," every user can both use the agent and view its full instructions (prompt/configuration). There is no way to allow all users to use an agent while restricting visibility of its instructions.
This poses a security risk when agent instructions contain sensitive information such as:
Use Case:
Our team has built the Approval agent, which contains sensitive vulnerability assessment thresholds, custom Jira field references, and approval workflow logic in its instructions. We need all users to interact with the agent, but exposing these implementation details to everyone creates a security concern.
Expected Behavior:
Provide a granular permission model for Rovo agents that separates:
View/Edit instructions permission — ability to see the agent's prompt, configuration, and knowledge sources (restricted to owners/editors only)
Hide instructions from users completely
Set instruction visibility permissions
Create truly private agent configurations