Five steps. Twenty minutes, most of it spent waiting for other people’s OAuth screens.
You need three things: a workspace (we create it on signature), an administrator on your identity provider, and one person willing to be the first agent owner. Pick someone whose week is full of drafting and chasing — the value shows up faster.
Agents read from your tools in place. Nothing is copied into a separate store unless you explicitly add it to the vault.
The fifth step is the one people skip. Do not. An agent that has watched three real workflows is worth more than one configured perfectly in the abstract.
One per person, named by that person. Private memory: what you tell your agent stays with your agent. It drafts in your voice because it has read what you have written, not because you filled in a tone slider.
One per team or company. Lives in channels rather than DMs. Pulls status, spots handoffs going stale, and writes the digest. It can see what the team has shared, never what an individual told their own agent.
You will rarely talk to it. It keeps the vault clean, signs every action into the ledger, and produces the export your DPO asks for. It is the reason compliance is not a project.
Promotion goes one way and needs a human. Nothing drifts upward on its own.
A skill is a saved way of doing something — a report format, a review checklist, a follow-up pattern. Skills start personal, get promoted to the team when they prove out, and are sealed into the ledger when they touch regulated work.
SAML against Okta or Entra ID. Provisioning is SCIM if you want it, manual if you do not. Three roles: member, workspace admin, and policy admin. Only a policy admin can change tier routing, and every change writes an entry naming who made it.