Skip to content

The datasheet for every AI agent

Research report · data-report

Admin controls: a census of 126 listings

55 of 126 listings answer yes for “Admin controls”. Counted from our own datasheet, with the query that reproduces every figure.

Sep 16, 2026updated Sep 16, 20262 min readSource-linked research

Admin controls, across 126 settled listings

  1. Yes55 of 126

  2. Qualified64 of 126

  3. No3 of 126

  4. Does not apply2 of 126

  5. Not established2 of 126

Of the 126 Published listings whose datasheet settles “Admin controls”, the largest group is “Qualified” at 64 (51%). Measured 2026-09-16.

Denominator: 126 Published listings whose datasheet settles “Admin controls”.Method: Counted from the stored datasheet answer for “Admin controls” across every Published listing, all of which have a recognised stored answer on that row.Measured .
Cite this chart

Reuse this chart anywhere, with credit. Paste this HTML — it links back to the report the numbers come from.

<a href="https://theagentsindex.com/blog/admin-policy-census/" target="_blank" rel="nofollow noopener"><img src="https://theagentsindex.com/charts/admin-policy-census.png" alt="Admin controls, across 126 settled listings — The Agents Index" title="Admin controls, across 126 settled listings — The Agents Index" width="640" loading="lazy" style="max-width:100%;height:auto" /></a>

Explore the matching agents

Admin controls · Datasheet criterion admin_policy · Report counted .

Current listings as of ; this set may differ from the report's original sample. Includes “Yes” and “Qualified” answers only. Read the conditions on qualified answers before treating them as a match. “No”, “Not applicable” and “Not established” answers are excluded.

View 119 current matching records
  • 11x Yes

    Approval workflows gate outgoing messages, and CRM access is constrained by granular read/write permissions.

    Source retrieved 2026-09-03

  • Ada Yes

    Admins constrain the agent with variable-based availability rules on knowledge and Playbooks, per-tool enablement, redactions on tool output, and four dashboard roles.

    Source retrieved 2026-09-09

  • AgentBridge Qualified

    Constraints exist but are per-machine developer settings (--safe, AGENTBRIDGE_* environment variables and .agentbridge/config.json), with no admin role and no centrally enforced policy.

    Source retrieved 2026-09-02

  • Agentix Labs Yes

    The control plane it delivers turns policy into enforced permission checks, approval gates, action budgets and stop conditions rather than a document.

    Source retrieved 2026-09-09

  • AgentsKit.js Qualified

    Constraints are real but expressed in code — validator chains, per-tool quotas and sandbox allow/deny lists — with no admin console or org-wide policy plane.

    Source retrieved 2026-09-09

  • Agno Yes

    JWT scopes gate every endpoint per agent and per tool, with roles assigned in the control plane and guardrails at runtime.

    Source retrieved 2026-09-02

  • Aide Yes

    Constraining the agent is the core of the product: it runs only team-written procedures, only within the account state configured, and escalates everything else.

    Source retrieved 2026-09-03

  • Aider Qualified

    Behaviour can be constrained per machine or per repo, disabling shell-command suggestions, auto-commits or git entirely, plus .aiderignore and a checked-in YAML config, but there is no org-level console enforcing policy across users.

    Source retrieved 2026-09-09

  • Aisera Agent Studio Yes

    Role-based access control is granular down to individual objects: privilege levels of Write, Read, Restricted or None per feature, with Restricted unlocking per-entity grants on workflows, integrations and channels.

    Source retrieved 2026-09-03

  • Amplemarket Yes

    Roles are granular and constrain what the agent and its users may do: admins set account-wide sending limits, recently-contacted thresholds, unsubscribe enforcement and LinkedIn sending windows, and can build custom roles scoping every object by ownership.

    Source retrieved 2026-09-10

  • Antigravity CLI Qualified

    Central administrative control arrives with the Google Cloud path; on individual plans the allow/deny/ask rules live in a user-editable settings file, and the vendor says admin URL allowlists are not yet honored.

    Source retrieved 2026-09-10

  • Artisan Yes

    Three built-in roles plus custom roles under Access controls, with members walled out of team, billing and Ava configuration, layered on top of per-campaign approval, banned-phrase and DNC constraints.

    Source retrieved 2026-09-10

  • AudioCodes Live Hub Qualified

    RBAC is real but fixed: admins assign users and API clients to predefined groups and cannot create a group or edit a policy of their own.

    Source retrieved 2026-09-03

  • Augment Code Yes

    A repo-committed settings file denies tools or specific shell commands on every cloud agent; Enterprise adds granular access controls and enforced budgets.

    Source retrieved 2026-09-02

  • AutoGen Qualified

    Constraints are developer-level: the runtime enforces identity and privacy boundaries, code executes in a Docker sandbox, and an approval callback can gate each execution. There is no admin console or policy engine.

    Source retrieved 2026-09-02

  • Auto-Respond Yes

    The agent is constrained by facts an admin approves - which services, prices, rules and answers it may use - plus per-source permission levels that decide who may edit those settings at all.

    Source retrieved 2026-09-11

  • Bitsclan IT Solutions Qualified

    Role-based access control and tenant isolation are described for the chatbot workspaces they deliver, but nothing states that an administrator can constrain what a delivered agent is allowed to do.

    Source retrieved 2026-09-11

  • Bland Qualified

    Admins constrain agent behaviour with time-based and continuous rails plus role-based access, but only Enterprise gets custom rails.

    Source retrieved 2026-09-11

  • Bolt Qualified

    Admins can force a deploy provider, lock site visibility, block GitHub, Stripe or Supabase and bar personal workspaces, but only from the Teams plan upward.

    Source retrieved 2026-09-11

  • Botpress Yes

    The Policy Agent gates every interaction against business rules, and inputs can be sandboxed with topics blocked outright; role-based access control, per-agent access control and trusted-domain restriction need Team or higher.

    Source retrieved 2026-09-02

  • Botsify Qualified

    An operator gets tenant isolation between client workspaces and usage-based billing controls to cap spend, but no policy engine constraining which actions or tools an agent may use is documented.

    Source retrieved 2026-09-13

  • Browserbase Qualified

    Admin roles and project access govern the dashboard only; what a session may do is set per session in code, not by policy.

    Source retrieved 2026-09-02

  • Cartesia Qualified

    Roles are Admin and Member only: an admin controls the org, invitations and members, not what an agent is permitted to do at runtime.

    Source retrieved 2026-09-02

  • Claude Agent SDK Yes

    The embedding app sets allow/deny rules, a permission mode and PreToolUse hooks; organization-managed settings can override a subagent's bypassPermissions.

    Source retrieved 2026-09-02

  • Claude Code Yes

    Managed and server-managed settings pin permission rules, model allowlists, telemetry and login method, and local settings cannot override them.

    Source retrieved 2026-09-02

  • Cline Yes

    Admins push remote configuration that constrains the agent itself: which providers and models are allowed, whether YOLO mode runs, and which MCP servers may be installed or added.

    Source retrieved 2026-09-12

  • CodeRabbit Yes

    Admins choose what happens past the review limit, set spending caps and seat modes, and scope which repositories and connections CodeRabbit may touch; custom RBAC is Enterprise.

    Source retrieved 2026-09-15

  • Codex CLI Yes

    requirements.toml pins approval policy, sandbox modes, permission profiles, allowed MCP servers and web-search mode; available on every plan including API-key use.

    Source retrieved 2026-09-02

  • CommentKeyword Qualified

    API tokens carry per-scope permissions and agents obey configured handoff rules, but no admin console policy controls over what agents may do are documented.

    Source retrieved 2026-09-05

  • Crescendo Yes

    Admins constrain both people and agent: role-based permissions govern who sees what, and the Safe Action Framework decides which actions the AI may take unattended.

    Source retrieved 2026-09-12

  • Cresta Yes

    Admins constrain agents at build time through escalation policies, compliance boundaries and a pre-built or custom guardrail library, with supervisory models enforcing policy in parallel and role-based access control for platform users.

    Source retrieved 2026-09-13

  • CrewAI Qualified

    Admins get feature-level roles plus entity permissions over individual automations, env vars, LLM connections and repos, but the pricing table lists RBAC as Enterprise-only.

    Source retrieved 2026-09-13

  • Cursor Qualified

    Teams admins enforce Privacy Mode, team rules and sandbox mode; repository blocklists, model/MCP access controls and auto-run, browser and network controls are Enterprise-only.

    Source retrieved 2026-09-02

  • Decagon Yes

    Admins constrain the agent two ways: role-based platform permissions, and AOP guardrails that gate refunds, escalations and brand voice.

    Source retrieved 2026-09-14

  • Deepgram Voice Agent API Qualified

    Role-based control exists over the account, not over the agent: owner, admin and member roles plus scoped API keys govern who may read usage, create keys or change billing. What the agent itself may say or call is bounded by your prompt and function definitions, with no admin-side policy engine documented.

    Source retrieved 2026-09-02

  • Devin Yes

    Admins bind network, MCP, git and GitHub-token restrictions to an org, an automation or a single session; enterprises can enforce them as a floor.

    Source retrieved 2026-09-02

  • Devin Desktop Yes

    Admins cap terminal auto-execution, set command allow/deny lists, restrict models by model or provider, gate MCP, deploys and the local agent, and push MDM policies to machines.

    Source retrieved 2026-09-03

  • Dify Yes

    Four built-in roles on Cloud gate who can build versus only use published apps; Enterprise adds workflow-level RBAC and SCIM.

    Source retrieved 2026-09-02

  • Dust Yes

    Admins cap which models and reasoning efforts each member may pick, set per-member spend limits and programmatic caps, and allowlist sandbox domains.

    Source retrieved 2026-09-09

  • ElevenLabs Agents Qualified

    Guardrails constrain what an agent may say and per-tool approval constrains what it may do, but Guardrails is in Alpha and enabling MCP servers is not restricted to admins.

    Source retrieved 2026-09-02

  • Elicit Qualified

    Admin powers cover membership, seats, usage visibility and what happens to a departing member's work; nothing published lets an admin constrain what the agent may do or which sources it may reach.

    Source retrieved 2026-09-14

  • Factory Qualified

    Org-managed settings cap autonomy and restrict models, MCP servers, commands and network; listed from Business upward, with full controls on Enterprise.

    Source retrieved 2026-09-02

  • Fin Yes

    Customer defines the agent's scope, boundaries and Procedures; data access can be restricted field by field.

    Source retrieved 2026-09-02

  • Firecrawl Qualified

    Threat Protection is a genuine organisation-wide floor, blocking risky URLs by blacklist, TLD, risk score or a Zscaler tenant, and rejecting per-request overrides with a 403 once disabled. It is double-gated: Enterprise plan and team-admin role only.

    Source retrieved 2026-09-03

  • GC AI Yes

    Admins gate what the agent may touch org-wide and per member - connectors disabled, read-only or full access, public chat sharing, Google Drive import, personal API keys and which model providers are used.

    Source retrieved 2026-09-14

  • Gemini Code Assist Qualified

    Admins gate access with IAM roles, set the project release channel and manage GitHub review config across repositories, but the agent's own tool allow/deny lists live in each developer's settings.json.

    Source retrieved 2026-09-02

  • Genspark Qualified

    Team admins can only govern connectors and roles org-wide, while restricting which agents and models a member may use is an Enterprise capability negotiated in the Order Form.

    Source retrieved 2026-09-15

  • GitHub Copilot Qualified

    Organisation and enterprise owners gate features, models, third-party agents, MCP servers and paid usage; enterprise settings override organisation ones. Individual plans have no admin layer.

    Source retrieved 2026-09-02

  • Glean Yes

    Admins gate model access, agent sharing scope and monthly spend by department, user or agent, and can disable premium models entirely.

    Source retrieved 2026-09-02

  • Google Agent Development Kit (ADK) Qualified

    Constraints exist but they are code, not a console: a plugin registered once on the runner applies its checks globally to every agent, tool and model call, and a developer must write it.

    Source retrieved 2026-09-15

  • goose Yes

    An administrator can pin an allowlist URL through GOOSE_ALLOWLIST so only approved MCP servers install, and can force approval modes and per-tool permissions through the config file.

    Source retrieved 2026-09-16

  • GPT Researcher Qualified

    Whoever runs the deployment constrains the agent through config and environment variables, but there is no admin console, role separation or policy enforced above the operator.

    Source retrieved 2026-09-16

  • Gumloop Qualified

    Anyone can gate their own agent's tool calls, but organisation-wide app policies, role-based access and model restrictions are Enterprise-only, so Pro governance stops at the agent.

    Source retrieved 2026-09-09

  • HeyRik Qualified

    An account owner constrains each agent individually, choosing which integrations it may use and which knowledge and custom-API tools it can call. No admin role, user management, or organisation-wide policy layer is documented.

    Source retrieved 2026-09-10

  • HOL Guard Yes

    Organisation policy on the Team plan is explicitly one that a local device cannot weaken, and a shared pack carries per-harness defaults, allowed and blocked publishers, domains and artifacts.

    Source retrieved 2026-09-07

  • IrisAgent Yes

    Admins constrain the agent through guardrails on sensitive operations, per-intent escalation rules, confidence thresholds and role-based access scoped per brand or region.

    Source retrieved 2026-09-03

  • Juggler Qualified

    Constraints are real but local and per-user: a strategy fixes which tools exist and what is auto-approved in a turn, and each MCP server takes an allowlist or denylist, yet there is no organisation-level console enforcing policy across users.

    Source retrieved 2026-09-17

  • Julius AI Qualified

    User roles and permissions are ticked for Business and Enterprise only; Enterprise adds fine-grained RBAC.

    Source retrieved 2026-09-02

  • Junie Qualified

    Admins enable Junie per profile and constrain models, providers, MCP servers and third-party agents, but only through AI Enterprise in IDE Services.

    Source retrieved 2026-09-02

  • Kilo Code Qualified

    Teams gets data-privacy controls on models and providers; allowlists, RBAC and policy enforcement are Enterprise.

    Source retrieved 2026-09-02

  • LangChain Yes

    Gateway spend and rate-limit policies, PII and secrets redaction, ABAC deny policies and dcode approval modes all constrain what an agent may do.

    Source retrieved 2026-09-02

  • Langflow Yes

    A superuser can hide components, templates, providers and models from the builder, block custom components, and restrict which fields API callers may override.

    Source retrieved 2026-09-03

  • LangGraph Qualified

    Workspace RBAC and tag-based ABAC are Enterprise-only; other plans default every user to Admin. Gateway cost controls, rate limiting and PII redaction are checked on all three plans.

    Source retrieved 2026-09-02

  • Leaping AI Qualified

    Identity and access management lets an administrator decide who may use the platform and what they may do there; constraints on the agent's own behaviour are set through conversation flows and transfer rules, not a documented policy engine.

    Source retrieved 2026-09-09

  • Letta Qualified

    Org roles gate who reaches an agent; what the agent may run is set per machine or project, not centrally by an admin.

    Source retrieved 2026-09-02

  • Lindy Yes

    Admins set which channels and folders Lindy may read, per-integration guardrails, per-person credit caps, who may approve external actions, and workspace toggles for meeting recording, email drafting and triage.

    Source retrieved 2026-09-02

  • LiveKit Agents Qualified

    Three dashboard roles only, and the role-based access row on the plan matrix is No for Build and Ship, Yes from Scale. Agent capability is bounded in code, not by console policy.

    Source retrieved 2026-09-02

  • LuMay Yes

    Constraints are enumerated concretely: least-privilege roles, tool allowlists, approval gates and spending limits, plus token-budget and latency caps set per agent in the runtime.

    Source retrieved 2026-09-09

  • Manus Qualified

    Team-only: four roles, a Security policies panel governing how members may join and access, and admin control over data migration. There is no policy engine constraining what the agent may do.

    Source retrieved 2026-09-02

  • Mastra Qualified

    RBAC restricts read/write/execute/delete per resource in Studio and on the API, but SSO and RBAC in production are Enterprise Edition features requiring a licence.

    Source retrieved 2026-09-02

  • Maven AGI Yes

    Policy is an org-level setting an admin configures once and the platform enforces on every action: routing rules, workflow policy, identity controls and deterministic logic, not per-conversation discretion.

    Source retrieved 2026-09-03

  • Microsoft Agent Framework Qualified

    Organisation-level policy needs the Purview middleware plus Microsoft Purview and an M365 E5 licence; everything in the framework itself (tool approval, ShellPolicy allow/deny lists, FIDES flow policies) is set by the developer in code, not by an admin.

    Source retrieved 2026-09-02

  • MindStudio Qualified

    Owner, Admin, Member and Guest roles plus per-agent Use Only or Edit Access govern who may do what, but Individual is single-user, and restricting which models and third-party services the workspace may call is Business-only.

    Source retrieved 2026-09-02

  • Moveworks Yes

    Role-based access scopes which tools and data an agent may touch, connectors are closed by default, and Policy Validators check rules before an action executes.

    Source retrieved 2026-09-02

  • Muse Code Qualified

    Central control is a managed hooks file plus per-machine approval modes and sandbox flags; no org-wide policy console is documented, and managed hooks themselves run outside the sandbox.

    Source retrieved 2026-09-02

  • n8n Yes

    RBAC at instance and project level (project roles on all Cloud plans, custom roles on Enterprise), plus instance policies to enforce 2FA and block specific nodes.

    Source retrieved 2026-09-02

  • OmniDimension Qualified

    Real per-user controls exist only for reseller accounts, which can switch dashboard menus on or off per client and cap their concurrency; ordinary team plans have no documented roles or permission settings, and agent limits are set per agent instead.

    Source retrieved 2026-09-09

  • OpenAI Agents SDK (Python) Qualified

    Constraints are code-level, not administrative: approval policies, MCP tool filters and sandbox network policy, all set by the developer.

  • OpenAI Realtime API Yes

    Admins constrain the agent per project: model allowlists or denylists, role-based permissions on /v1/realtime requests, IP allowlists and data-retention settings.

    Source retrieved 2026-09-02

  • OpenClaw Yes

    Named operator roles cap scopes, agents and session access per person; separately, tool policy decides which tools exist, permission modes bound the filesystem, and exec approvals gate commands.

    Source retrieved 2026-09-02

  • OpenCode Yes

    Permissions are set in config globally or per tool, so an operator can deny edits or shell commands outright.

    Source retrieved 2026-09-02

  • OpenHands Qualified

    Admins can constrain the secrets, tools and domains an agent may reach and halt risky actions, but that control plane is Enterprise; Cloud Organizations only reach as far as default LLMs and budget caps.

    Source retrieved 2026-09-02

  • Perplexity Qualified

    User management arrives with Enterprise Pro; role-based access control and custom roles sit in the custom-priced governance tier and the comparison table marks that row 'Contract required'.

    Source retrieved 2026-09-02

  • Pickaxe Yes

    Owners restrict what agents may do for whom: access groups decide which deployments a user reaches, each user gets a usage budget, and users can be banned by email or IP.

    Source retrieved 2026-09-09

  • PolyAI Yes

    Fifteen navigation areas each set to None, Read or Edit, expandable to individual items, over an Admin/Member account role.

    Source retrieved 2026-09-02

  • Pydantic AI Qualified

    Constraints are code, not a console: guardrail callables gate prompts, tool calls and outputs, alongside shell allowlists, tool approval and spend limits. Role-based control arrives only with Logfire Enterprise.

    Source retrieved 2026-09-02

  • Qualified Yes

    Two constraints are documented: goals, guardrails and rules-of-engagement configured in Agent Studio, and the Salesforce integration user's object and field permissions bounding what the agent can read or write.

  • Relevance AI Qualified

    Approval gates, spend and usage limits on all plans; RBAC and fine-grained asset controls are Enterprise-only

    Source retrieved 2026-09-02

  • Replit Agent Qualified

    Enterprise account admins decide which model providers and models Agent may use, per account and per Workspace, and routing cannot override the policy.

    Source retrieved 2026-09-02

  • Retell AI Qualified

    Role-based access control is sold as an Enterprise line, marked absent for pay-as-you-go in the plan table, yet the docs describe Admin/Developer/Member roles with no tier restriction; API keys can be scoped read or edit on any plan. Contradiction recorded in notes.

    Source retrieved 2026-09-02

  • Ringly Yes

    An admin can switch individual skills off, cap the order value the agent may cancel and refund, restrict escalation to business hours, and block callers outright, all from the dashboard.

    Source retrieved 2026-09-09

  • Rox Qualified

    Org-wide defaults, permission sets and field-level access bound what users and their agents may touch, and agents inherit the acting user's clearance - but Role-Based Access Control and User & Team Management are dashed for Individual and ticked from Teams up.

    Source retrieved 2026-09-03

  • SafeNet Creations Qualified

    Access controls and action boundaries exist but are set by SafeNet inside the written scope; nothing indicates a client-side console for changing them afterwards.

    Source retrieved 2026-09-04

  • Salesforce Agentforce Yes

    Admins author the agent's topics, actions and guardrails; the Trust Layer additionally masks PII/PCI and filters toxic output, and agent data access honours existing permissions and sharing rules.

    Source retrieved 2026-09-03

  • SalesTouch Yes

    Daily action limits, working hours, pacing, cooldowns and approval controls are configurable and included on both plans.

    Source retrieved 2026-09-03

  • Sierra Yes

    Goals, guardrails and topic and keyword filters bound what the agent may say or do, and Horizon lets you mark the steps that need human sign-off.

    Source retrieved 2026-09-03

  • Sim Qualified

    Enterprise Access Control groups restrict which model providers and block types users may run, enforced in the executor; not available below Enterprise.

    Source retrieved 2026-09-03

  • sipgate flow Qualified

    The sipgate account separates admin from restricted users, which governs configuration rights, not a policy engine limiting what the agent may do mid-call.

    Source retrieved 2026-09-03

  • SkipCalls Qualified

    Owner and Admin roles gate billing, numbers, API keys and integrations, but any member who can see the workspace can manage every agent, so there is no per-agent policy scope.

    Source retrieved 2026-09-03

  • Spiich Yes

    Per-agent switches gate email, Slack, enrichment and table writes, Proposal mode stages every CRM change for review, and admins choose which CRM objects the agent may touch.

    Source retrieved 2026-09-15

  • StackAI Yes

    Admins constrain the agents centrally: enable or disable individual LLMs, apps and tools, force org API keys, restrict who may publish and require SSO on interfaces.

    Source retrieved 2026-09-09

  • Synthflow Yes

    Agency admins grant or revoke per-subaccount permissions for actions, agent types, editor options and integrations.

    Source retrieved 2026-09-03

  • TecAdRise Qualified

    Limits on what an agent may do are set by TecAdRise during design and operations; buyers receive outputs and connectors rather than builder access, so they cannot change policy themselves.

    Source retrieved 2026-09-12

  • TelEcho Qualified

    Every agent is constrained at setup by guardrails and escalation rules, but the administrative controls that decide who may change them - RBAC, region pinning, retention controls - are listed as Enterprise-plan lines.

    Source retrieved 2026-09-16

  • Telnyx Voice AI Agents Qualified

    Owners constrain people through CRUD permission groups and constrain the agent by which tools, integrations and MCP servers are attached, but Telnyx warns that not all V2 services are exposed to organization permissions.

    Source retrieved 2026-09-09

  • TinyFish Qualified

    Role-based access over credential handling is described as an Enterprise governance capability; no self-serve policy controls are published.

    Source retrieved 2026-09-03

  • UiPath Agent Builder Qualified

    Admins get Automation Ops governance policies that can override an agent's model settings, plus custom roles and access policies, but both rows carry an em dash on the Basic tier and start at Standard.

    Source retrieved 2026-09-03

  • Undermind Qualified

    An admin dashboard and sitewide organizational login exist at Enterprise; no published control over what the agent itself may do.

    Source retrieved 2026-09-03

  • Unify Yes

    Admins alone edit Plays and exclusion settings, and exclusions bar the agent from acting on named companies or people.

    Source retrieved 2026-09-03

  • Vapi Yes

    Per-tool rejection conditions withhold an action, API keys are scoped to specific origins and assistants, and prompt guardrails override other instructions.

    Source retrieved 2026-09-03

  • Vecbase Yes

    Connector scopes, capabilities and file spaces are granted per agent and revocable, and sensitive actions can require human approval.

    Source retrieved 2026-09-03

  • Vellum Qualified

    The owner (guardian) constrains the agent tightly with risk tiers, deny-wins trust rules and per-Slack-channel tool profiles, but there is no organisation admin who can impose policy on someone else's assistant.

    Source retrieved 2026-09-03

  • VoiceAgents Qualified

    Tenants configure agent call settings and their own recording and transcript retention, but no role-based permission model or policy engine for authorised users is documented.

    Source retrieved 2026-09-03

  • Warmly Yes

    Advanced role-based access control with IP restrictions and configurable retention.

    Source retrieved 2026-09-03

  • Warp Qualified

    Admins set org-wide autonomy per action type plus regex command allowlists and denylists, and can lock users out of overriding them. On Free most settings are fixed; configurability starts at Business and is complete on Enterprise.

    Source retrieved 2026-09-03

  • Zed Qualified

    Business admins can disable Zed-hosted models, Edit Predictions, feedback sharing and collaboration org-wide; the controls do not reach BYOK, gateways, local models, External Agents or Terminal Threads.

    Source retrieved 2026-09-03

  • Zencoder Yes

    Admins cap how much of the shared pool each user may burn, choose which repositories agents can index and read, and can restrict repository access to named emails.

    Source retrieved 2026-09-09

  • Zendesk AI agents Yes

    Reasoning controls on every plan, automated QA scoring of each interaction, and Enterprise approval workflows.

    Source retrieved 2026-09-03

  • zot Qualified

    Constraints are per-machine, not centrally administered: a zotfile manifest caps file and bash access, and jail_by_default in config.json starts every run confined to the working directory.

    Source retrieved 2026-09-03

The population

126 listings in this index are Published. This is the population as of 2026-09-16. 126 of the 126 published listings in this index carry a settled answer for “Admin controls”. That row asks: Can an admin constrain what the agent may do? Every listing in the index is settled on this row, so nothing is left out.

Findings

  1. 55 of the 126 settled listings answer “Yes” for “Admin controls”. That is 44% of the settled set.

  2. 64 of the 126 settled listings answer “Qualified” for “Admin controls”. That is 51% of the settled set.

  3. 3 of the 126 settled listings answer “No” for “Admin controls”. That is 2% of the settled set.

  4. 2 of the 126 settled listings answer “Does not apply” for “Admin controls”. That is 2% of the settled set.

  5. 2 of the 126 settled listings answer “Not established” for “Admin controls”. That is 2% of the settled set.

1 of those yes answers is Codex CLI, which still answers yes for “Admin controls”. Its listing carries the stored answer and links to the source recorded for it. This is one worked example, not an independent audit of every source in the census.

What we counted, and how

Each figure above is a count over the “Admin controls” row of the listing datasheet, taken from the same stored answer the listing page renders. The denominator is the 126 listings whose answer is settled, meaning one of yes, qualified, no, does not apply, not established. On this row that is the whole index, because every listing has a recognised stored answer. Every number here is stored with the read-only query that reproduces it and re-run every sixty seconds against the live corpus, so a figure that stops reproducing surfaces as drift rather than as a stale sentence nobody notices. Our full method covers how a datasheet row is settled in the first place.

Limitations

This counts stored datasheet answers, not independently tested capabilities. A sourced answer can record a vendor statement or our reading of published evidence; this census does not re-fetch those sources. “Not established” means we have not established an answer. That can reflect vendor nondisclosure, blocked evidence, or unfinished research, not a no. An absent or unrecognised answer is excluded rather than treated as a researched finding. The figures are restated when the stored corpus changes; the date above is the count used for this published version, not a new verification of the vendors.

Get the next report

New agents rankings and fresh data reports. One short email, one-click unsubscribe.