ThinkingAI Logo
Back to Product Updates
GovernanceJuly 7, 2026

Platform Governance and Cost Control: roll Agents out company-wide, keep the guardrails

New admin controls for running Agents at company scale: unified member and permission management, an isolated sandbox for every user, and token-based cost caps at both the company and individual level.

A rounded boundary enclosing neat work-units, with a lock at one corner and a cap meter, signaling control.

New in the Agentic Engine: a set of admin controls for running Agents safely at company scale, available now. Bring people on and set their permissions in one place, give each user an isolated sandbox so one person's work never touches another's, and cap Agent spend at both the company and individual level. The goal is straightforward. Roll Agents out to the whole company, not just a pilot group, without losing track of who is using what and how much it costs.

In short, leadership gets real cost guardrails and clean separation between users, so a broad rollout stays under control.

An isolated sandbox for every user

My Sandbox is a dedicated cloud workspace for each user, pre-loaded with a coding agent. It works like a local development environment, but without the risk of one person's activity affecting anyone else's.

  • A dedicated space per person. Each user gets their own cloud workspace, so their activity stays contained and cannot spill into someone else's.
  • Works like local dev. Browse files, run work, and preview results the way you would on a local machine.
  • No environment pollution. Isolation protects security and data integrity across the team as you add more people.

Why it matters: a broad rollout only works if one user's activity can't destabilize everyone else's. Isolation is what makes it safe to add people at scale.

Planned next: more agent options inside the sandbox, beyond the pre-loaded coding agent. That is on the roadmap and not available yet.

An even grid of separated cells, each holding one contained work-unit, showing isolated per-user sandboxes.

Unified member and permission management

Managing Agent access now lives in one place. Admins add members, delegate admin rights, and assign a sandbox to a new user at the moment they are brought on.

  • Add members and set roles from a single view, instead of piecing permissions together across scattered settings.
  • Delegate admin rights, so responsibility can be shared as the team grows.
  • Assign a sandbox at onboarding, so a new user is ready to work from the start.

Why it matters: less time spent managing permissions in separate screens, and a clear record of who has access to what.

Cost controls at the company and individual level

You can now set token-based usage caps on Agent spend, at both the company level and the individual level. Leadership gets a real ceiling on cost instead of open-ended spend.

  • Company-level cap to hold total Agent spend to a known ceiling.
  • Individual-level cap, so no single user's usage runs away.
  • Token-based limits tied to actual usage.

Why it matters: broad adoption is only sensible when spend is predictable. A cap turns "we think this is affordable" into a number you set in advance.

Planned next: fully custom limit rules and per-member model access control. Both are on the roadmap and not available yet.

Two upright columns filled partway under a horizontal cap line, showing company and individual spend limits.

How It Works

Bringing a user into a governed rollout takes three steps.

  1. Add the member. Bring the person in and set their role, delegating admin rights if you need to.
  2. Assign an isolated sandbox. Give them their own workspace at the same time, so their activity stays contained.
  3. Set a cost cap. Apply a token-based usage limit at the individual level, within the company-level ceiling.
A left-to-right flow: add a member, assign an isolated cell, then a container capped by a spending line.

Getting Started

These controls live in the admin settings of the Agentic Engine. Add members and delegate admin rights from one place, assign each new user an isolated sandbox as you bring them on, and set token-based cost caps at the company and individual level. Fully custom limit rules and per-member model access control are planned for a future release. Together, these give leadership what a company-wide rollout needs: clear access, clean separation between users, and a spending ceiling you set in advance.