Doozy for teams and enterprises
Doozy gives teams a shared place to delegate work to persistent Doozies (aka AI agents, bots, or teammates) while keeping ownership, evidence, approvals, and execution visible. Members can respond in the same conversations, update shared to-dos and captures, assign work to a person or Doozy, and watch status change as work moves. Administrators manage people, model providers, connected apps, and security policies at the organization and workspace levels.
How team workspaces operate
An organization can contain several workspaces. Each workspace has:
- its own members and roles;
- a team of Doozies;
- workspace connections and toolkits;
- one persistent Morph environment;
- conversations, to-dos, files, schedules, and approvals;
- workspace-level usage and policy controls.
Members can each arrange open work in their own tabs (aka task contexts, work contexts, or sessions). The conversations, to-dos, captures, assignments, files, and status inside the workspace are shared according to access, so another member can continue the work with its context intact.
All Doozies in one workspace share that workspace’s Morph files and authenticated sessions. Different workspaces are the isolation boundary for execution state and connections.
Plan the workspace structure
Create separate workspaces when teams need different membership, customers, production environments, credentials, retention, or risk policies. Avoid one organization-wide workspace merely to make context easy to find.
Before rollout, decide:
- which initial kinds of work are appropriate;
- who owns each workspace;
- which systems may be connected;
- what information may enter model context;
- which actions always require approval;
- how generated work will be reviewed and retained;
- who handles incidents and access removal.
Start with a small group and measurable outcomes before expanding access.
Roles and access
Organization and workspace roles determine who can invite members, create Doozies, manage connections, change policies, approve actions, and inspect usage.
Use groups for repeatable access patterns. Keep administrative roles limited and review them periodically. A member’s ability to see or approve work should match their operational responsibility.
Morph isolation
Each workspace receives a managed Morph environment. Doozies run as non-root users and use workspace-scoped storage and credentials. Doozies inside that workspace are collaborators, not mutually isolated tenants.
For stronger separation, place production and development, different customers, or legally distinct data sets in separate workspaces. Use separate provider accounts or service identities where appropriate.
Admins can suspend, recover, or reset a workspace environment. Recovery should preserve durable files and sessions; reset can revert recent state. Preserve critical work in source control or another system of record.
Network controls
Enterprise policies can restrict internet access, approved domains, egress, and connected services. Where supported, use static egress addresses to allowlist Morph traffic in company systems.
Some websites block cloud browsers or require human verification. Prefer supported connections and APIs for stable work. Don’t bypass provider security controls.
Connections and MCP policy
Admins can control which app connections (aka connectors or integrations), MCP servers, and toolkits (aka plugins or tool sets) are available. A workspace connection can then be assigned to selected Doozies.
Review the data and actions exposed by each connection. Disabling a connection prevents new use but may not revoke tokens already issued by the provider; revoke those at the source when removing access.
Model providers and Codex
Organizations can approve model providers and authentication methods. Codex can use eligible ChatGPT subscription access through OpenAI sign-in or usage-based API-key access. OpenAI workspace policies, retention, residency, roles, and plan eligibility continue to apply to that usage.
Managed teams should prefer organization-approved authentication over personal credentials. Never distribute one person’s cached authentication file to several users or workspaces.
Approvals and governance
Organization policy can require approval for sensitive action categories across all workspaces. Workspace and Doozy policies may add stricter rules but can’t weaken organization requirements.
Use the linked to-do, conversation, proposed payload, approver, and result as the audit trail. Export or retain records according to your organization’s governance requirements.
Privacy and retention
Configure retention and deletion for conversations, files, to-dos, memories, execution records, and Morph state. Connected systems may retain their own copies and logs.
Confirm the data-handling terms and controls for every selected model and app provider. Enterprise commitments apply only to the services and plans covered by the applicable agreements.
Usage and billing
Admins can review usage by organization, workspace, provider, and member where supported. Doozy service usage and third-party provider billing may appear separately.
Set budgets and alerts before enabling large recurring workloads. Parallel Doozies, browser-heavy work, and long-running Codex to-dos can increase resource consumption.
Rollout checklist
- Create workspace boundaries and owners.
- Approve providers and least-privilege connections.
- Configure organization and workspace approval policies.
- Pilot two or three read-heavy kinds of work.
- Review evidence quality, failure handling, and audit records.
- Add narrow write access and recurring schedules.
- Train members to handle takeover, secrets, and approvals.
- Revisit membership, connections, and policies regularly.
Frequently Asked Questions
Should different customers or departments use separate workspaces?
Use separate workspaces when membership, credentials, data, policies, billing, or environments need distinct boundaries. Doozies inside one workspace share its security boundary.
Can admins control which apps Doozies connect?
Yes. Organization and workspace policy can restrict connections, scopes, toolkits, model providers, and approval requirements. Provider-side admin consent may also apply.
Does Doozy support managed identity and SSO?
Enterprise identity can be governed through organization-approved sign-in, membership, domain, and provider policies. Confirm the supported identity options for your plan and rollout requirements.
Can admins audit what Doozies did?
Admins can review workspace activity, to-dos, conversations, approvals, connection usage, and provider usage where supported. External systems may keep their own audit records as well.
How should teams manage parallel Doozy work?
Assign one accountable coordinator, give each Doozy a clear output and boundary, and use dependencies for shared work. Repositories should use separate branches or worktrees before results are reconciled.
Can several people collaborate on the same Doozy work?
Yes. Members with access can respond in shared conversations, edit or reassign to-dos, work with captures, and follow live status. Each person can keep the work they need open in their own tabs.
Looking for something broader? Read the general FAQ.