Delegated management

Delegated management lets members of chosen security groups edit a profile in the Endpoint AI console without holding any provisioner admin role. A team lead can curate their own team's skills while IT keeps control of who receives what.

How it works

Each profile has a Delegated management card on its detail page. As the card explains, members of the selected security groups may edit that profile in the Harriet Endpoint AI console without full Manage Harriet Endpoint AI access. A user with that permission picks the groups with the Management security groups selector (Add security groups…); the Profiles table shows the result in its Delegated managers column.

Once delegated, those members see a Profiles entry in the console navigation even without any provisioner role. Their view is filtered to the profiles delegated to their groups — if none are, the list reads "No profiles are delegated to your security groups."

Typical use

The common pattern is a per-team profile owned by the team itself. IT creates a "Sales" profile, assigns it to the Sales team, and delegates its management to a security group containing the sales lead. From then on the lead adds and removes skills, tunes the global rules, and adjusts transport overrides for their own people, without a ticket to IT and without gaining access to any other team's configuration.

The review workflow still applies: a skill a delegate adds while it is in review shows the Awaiting approval chip and is not pushed to desktops until approved, so delegation does not bypass governance.

What delegates can and cannot do

Delegates canDelegates cannot
Edit the profile's name and descriptionCreate or delete profiles
Add, remove, and reorder skills in the profileChange who receives the profile — the recipients list is read-only for them
Edit the Harriet Desktop global rules (AGENTS.md)Set or clear the Default profile flag
Manage Desktop MCP transport overridesChange which security groups hold the delegation

The boundary is deliberate: delegation hands over a profile's contents, never its reach. The profile detail page states it directly — delegated profile managers can edit the profile contents but cannot change the assignment list. Adding a team or person still requires Manage Harriet Endpoint AI, so widening a profile's audience always goes through an admin.

Limits of the delegation

Delegation is scoped to profile editing only. It grants nothing else in the console: delegates without a provisioner view role do not get the organization-wide screens, and the people and teams pickers stay gated behind provisioner access. They can load the skill and connector lists needed to edit their profiles, and no more. Full admins retain visibility and control over every profile, delegated or not — see Roles and permissions for how provisioner roles fit together.

💡

Security groups are managed alongside your teams in Company settings. Keep management groups small — one or two accountable owners per profile beats delegating to a whole department. See Teams and people.