> ## Content Index
> Fetch the complete content index at: https://blog.aperion.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# Glean Agents Governance: Permissions, Tools and Audit
- URL: https://blog.aperion.ai/glean-agents-governance-guide/
- Published: 2026-10-06T21:41:41.000Z
- Updated: 2026-10-06T21:41:41.000Z
- Description: Glean agents read what each user can read and act in connected apps. How to govern them in seven steps, from source permissions to one audit record.
- Author: Craig Alberino
- Tags: Guides, AI Agents, AI Governance

*Updated October 6, 2026\. Part 3 of APERION's Agent Platforms series.*

**Glean governs agents through the permissions your source systems already enforce, plus agent roles, publish approval, confirmation on write tools, and usage limits.** To govern Glean agents well, clean up source-system permissions before you widen agent use, restrict who can publish and share agents, keep confirmation on for write tools, scope the MCP tools Glean can call, and join Glean's three log streams into one record. Glean runs the model calls inside its own platform, so the common control points for an enterprise are the tool path and the trace export.

Glean reported $300 million in annual recurring revenue in May 2026 ([Glean, May 2026](https://www.glean.com/press/glean-surpasses-300m-arr-unrivaled-enterprise-context-fuels-ai-adoption)). Its agents read across the company's connected applications and act in them, and Glean works in both directions over MCP: its agents call remote MCP servers (in beta), and assistants such as Claude, ChatGPT, Cursor and Copilot Studio call Glean's MCP server ([Glean MCP documentation](https://docs.glean.com/administration/platform/mcp/about)). Governance has to cover both directions.

## What Glean Ships for Governance

| Control                    | What it does                                                                                                                              | Default or status                                                                     |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- |
| Permission-aware retrieval | Agents and MCP clients see only what the invoking user can see in the source system                                                       | Default; an agent with a service credential (beta) uses that credential's permissions |
| Agent roles                | Agent Moderator, Departmental Agent Moderator and Agent Creator                                                                           | Members can create, publish and share agents by default                               |
| Publish approval           | Require approval never, for company-wide sharing, or for any sharing                                                                      | Set by the admin                                                                      |
| Write-tool confirmation    | Write tools pause for the user to confirm before they run                                                                                 | On in the web app; Slack and Teams behavior unchanged                                 |
| Model controls             | Glean-managed model key or your own key; models restricted by department or identity group                                                | Set by the admin                                                                      |
| Usage limits               | Limits by organization, user, agent or department, with alerts                                                                            | Set by the admin                                                                      |
| Protect+ AI security       | Block or flag prompt injection, jailbreaks, malicious code and harmful content in inputs, outputs, retrieved documents and tool responses | Separately licensed                                                                   |
| Agent Access Policies      | Rules on tool calls before they run and on tool output after, scoped by identity group, agent and tool                                    | Beta, with Protect+                                                                   |
| Agent identity             | Agents act through scoped service credentials and record the person who triggered them                                                    | Beta                                                                                  |

Sources: Glean documentation on [agent access](https://docs.glean.com/administration/managing-agents/agent-access), [tool confirmation](https://docs.glean.com/tools/human-in-the-loop-experience-for-tools), [Protect](https://docs.glean.com/administration/protect/overview), [AI security](https://docs.glean.com/administration/protect/ai-security/introduction), [Agent Access Policies](https://docs.glean.com/administration/protect/ai-security/agent-access-policies) and [agent identity](https://docs.glean.com/administration/agent-identity/overview), verified October 6, 2026.

## Where Glean's Control Points Are

**Model calls stay inside Glean.** Customers choose a Glean-managed key with automatic routing or their own key: OpenAI, Azure OpenAI or Anthropic on any deployment, or Vertex AI or Amazon Bedrock when that cloud matches the Glean deployment ([Glean LLM settings](https://docs.glean.com/administration/llms)). Glean documents zero-retention commitments with its model providers ([Glean model choice](https://docs.glean.com/get-started/golive/model-choice)). Apart from an optional custom base URL for a customer's own Anthropic key, Glean documents no option to send its model calls to a customer-run endpoint ([configure LLMs](https://docs.glean.com/administration/configure-llms)).

**Tool calls are reachable.** Glean agents call remote MCP servers that you connect, in beta ([Glean remote MCP servers](https://docs.glean.com/administration/tools/connect-remote-mcp-servers-to-glean)), and Glean's MCP gateway brings outside tools into Glean's own MCP servers. Glean's documentation states that through the gateway, "by default, all tools are on for all users" ([Glean MCP gateway](https://docs.glean.com/administration/platform/mcp/mcp-gateway)). In the other direction, Glean's MCP server applies the user's permissions: "If a user cannot see or access something in Glean, then they cannot see or access it through MCP" ([Glean MCP security](https://docs.glean.com/administration/platform/mcp/security)).

**Logs come in three streams.** Admin audit logs record configuration changes, keep 30 days by default, and leave out end-user activity ([admin audit logs](https://docs.glean.com/administration/management/audit-logs/admin-audit-logs)). Customer event logs cover searches, chats, agent runs, tool calls, MCP calls and model calls, delivered to object storage ([event log dictionary](https://docs.glean.com/administration/gce-logs/data-dictionary)). Trace export sends agent runs, tool calls and model calls over OTLP to one endpoint per configuration, without historical bulk export or delivery guarantees ([trace export](https://docs.glean.com/administration/agent-trace-export)).

## How to Govern Glean Agents in 7 Steps

### 1\. Fix permissions at the source first

Glean agents read what each user can read. Content shared too broadly in a file store, wiki or ticketing system becomes reachable by every agent that user runs. Run a sensitive-content scan, close broad shares on the sources with the most sensitive data, and only then widen agent use.

### 2\. Decide who builds, publishes and shares agents

Members can create, publish and share agents by default. For a regulated rollout, limit creation to named groups, require approval for company-wide sharing, and keep publishing through embedding, API and Slack off until an agent has an owner and a review.

### 3\. Keep confirmation on for write tools, and know where it applies

Write tools pause for the user to confirm in Glean's web app. Glean states that Slack and Teams behavior remains unchanged, so review which agents run in chat channels. Skipping confirmation takes two switches, one by the admin and one by the agent's builder; allow it only for low-consequence writes.

### 4\. Scope the MCP tools Glean can call

Restrict gateway tools to named groups, since all tools are on for all users by default. Connect remote MCP servers through per-user OAuth where the vendor template supports it, so each call acts as the person who made it. Put the remote servers you run behind a gateway that applies tool rules and records each call.

### 5\. Restrict models and keys

Use your own key where your contracts require it, and restrict models by department or identity group. For Vertex AI or Amazon Bedrock keys, confirm the cloud matches your Glean deployment, since Glean does not support cross-cloud access for those providers.

### 6\. Set usage limits

Set limits by department and by agent, with alerts. When a limit is reached, Glean lets the action in flight finish and then blocks billable use for the rest of the calendar month ([Glean usage limits](https://docs.glean.com/administration/management/usage/set-usage-limits-and-alerts)).

### 7\. Join the three log streams into one record

Request delivery of admin audit logs to your storage, since it is off by default. Stream customer event logs to the same place, and export traces to your OpenTelemetry collector. Map all three to one schema keyed on the user and the agent, and extend retention past the 30-day default.

## The Risk Pattern for Enterprise Search Assistants

An assistant that reads everything a user can read also reads content an outsider can place in front of it: a shared document, an email, a calendar invite. EchoLeak in Microsoft 365 Copilot ([CVE-2025-32711](https://nvd.nist.gov/vuln/detail/CVE-2025-32711)) and GeminiJack in Gemini Enterprise, both disclosed in 2025, used planted content to make an assistant send data out. Neither involved Glean. The pattern applies to every permission-aware assistant. Scan retrieved documents and tool responses for injected instructions, limit the outbound actions agents can take, and require confirmation on anything that sends data outside the company.

## Operating Limits

- **Permission-aware retrieval inherits your permissions.** Over-sharing in a source system becomes over-sharing in every agent.
- **Confirmation on write tools covers the web app.** Check chat-channel agents separately.
- **Admin audit logs record configuration.** Agent activity lives in the event logs and traces.
- **Trace export has no delivery guarantee.** Treat the event logs as the record of activity.
- **Model calls run inside Glean.** Govern them through Glean's model and key settings.

## How APERION Fits

For Glean, APERION's Smartflow works on the tool path. Glean agents can call Smartflow's MCP gateway as a remote MCP server, and the gateway applies tool rules to every call, sends out-of-authority calls to a person with approval rights, and records each call. Glean's trace export can feed the same record after the fact, marked as ingested rather than enforced inline. [Talk to APERION](https://aperion.ai/contact).

## More in This Series

- [How to govern AI agents across platforms](https://aperion.ai/blog/govern-ai-agents-across-platforms-guide/)
- [CrewAI security and governance](https://aperion.ai/blog/crewai-security-governance-guide/)
- [Agentforce governance](https://aperion.ai/blog/agentforce-governance-guide/)
- [Amazon Bedrock AgentCore governance](https://aperion.ai/blog/aws-bedrock-agentcore-governance-guide/)
- [Microsoft Copilot agent governance](https://aperion.ai/blog/microsoft-copilot-agent-governance-guide/)
- [Google, ServiceNow, OpenAI, Anthropic and LangChain](https://aperion.ai/blog/google-servicenow-openai-anthropic-agent-governance-guide/)

## Frequently Asked Questions

### How does Glean enforce permissions for agents?

By default, Glean agents, its assistant and its MCP server return only content the invoking user can access in the source system, whoever built or published the agent. With agent identity, in beta, an agent runs with a fixed service-credential permission set instead.

### Can Glean agents take actions in other applications?

Yes. Glean agents use write tools and remote MCP servers to act in connected applications. Write tools pause for user confirmation in the web app unless an admin and the agent's builder both allow them to run without it.

### Who can create and publish Glean agents?

By default, members can create, publish and share agents. Admins can assign Agent Moderator, Departmental Agent Moderator and Agent Creator roles, and require approval before agents are shared company-wide or at all.

### Can I use my own LLM with Glean?

Glean supports a customer key with OpenAI, Azure OpenAI or Anthropic on any deployment, and with Vertex AI or Amazon Bedrock when that cloud matches the Glean deployment. Apart from an optional custom base URL for an Anthropic key, it does not document routing its model calls to a customer-run endpoint.

### Does Glean support MCP?

Yes, in both directions. Glean agents call remote MCP servers, in beta, and Glean's own MCP server gives other assistants permission-aware access to Glean search, chat and agents.

### How do I audit what Glean agents did?

Use the customer event logs for searches, chats, agent runs, tool calls and model calls, and the OTLP trace export for run-level detail. The admin audit log records configuration changes only, keeps 30 days by default, and is delivered to your storage on request.

### What is Glean Protect+?

Protect+ is a separately licensed add-on that adds ongoing sensitive-content scans and AI security policies that block or flag prompt injection, jailbreaks, malicious code and harmful content. Agent Access Policies, in beta, are part of it.

---

*Craig Alberino is the CEO and Founder of [APERION](https://aperion.ai), which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. [Learn more about Smartflow →](https://aperion.ai/products/smartflow)*