Delegated management
Delegated management lets members of chosen security groups edit a profile in the Endpoint AI console without holding any provisioner admin role. A team lead can curate their own team's skills while IT keeps control of who receives what.
How it works
Each profile has a Delegated management card on its detail page. As the card explains, members of the selected security groups may edit that profile in the Harriet Endpoint AI console without full Manage Harriet Endpoint AI access. A user with that permission picks the groups with the Management security groups selector (Add security groups…); the Profiles table shows the result in its Delegated managers column.
Once delegated, those members see a Profiles entry in the console navigation even without any provisioner role. Their view is filtered to the profiles delegated to their groups — if none are, the list reads "No profiles are delegated to your security groups."
Typical use
The common pattern is a per-team profile owned by the team itself. IT creates a "Sales" profile, assigns it to the Sales team, and delegates its management to a security group containing the sales lead. From then on the lead adds and removes skills, tunes the global rules, and adjusts transport overrides for their own people, without a ticket to IT and without gaining access to any other team's configuration.
The review workflow still applies: a skill a delegate adds while it is in review shows the Awaiting approval chip and is not pushed to desktops until approved, so delegation does not bypass governance.
What delegates can and cannot do
| Delegates can | Delegates cannot |
|---|---|
| Edit the profile's name and description | Create or delete profiles |
| Add, remove, and reorder skills in the profile | Change who receives the profile — the recipients list is read-only for them |
| Edit the Harriet Desktop global rules (AGENTS.md) | Set or clear the Default profile flag |
| Manage Desktop MCP transport overrides | Change which security groups hold the delegation |
The boundary is deliberate: delegation hands over a profile's contents, never its reach. The profile detail page states it directly — delegated profile managers can edit the profile contents but cannot change the assignment list. Adding a team or person still requires Manage Harriet Endpoint AI, so widening a profile's audience always goes through an admin.
Limits of the delegation
Delegation is scoped to profile editing only. It grants nothing else in the console: delegates without a provisioner view role do not get the organization-wide screens, and the people and teams pickers stay gated behind provisioner access. They can load the skill and connector lists needed to edit their profiles, and no more. Full admins retain visibility and control over every profile, delegated or not — see Roles and permissions for how provisioner roles fit together.
Security groups are managed alongside your teams in Company settings. Keep management groups small — one or two accountable owners per profile beats delegating to a whole department. See Teams and people.