Overview
As Digital Employees spread across a workspace, governance answers: who can see and manage whom, how delegation hierarchies appear on the mesh, and what evidence exists when something changes. Cowork surfaces governance through the Mesh Canvas, Cowork Layers, and employee drawers — not through a separate admin console inside Cowork.What you see on the mesh
Cowork Layers
The Cowork Layers control (action bar on Mission Control) filters whose employees appear on your canvas:- My area — employees you own
- Direct reports — employees owned by people who report to you (when you are a manager)
- Their employees — extend down the org tree as your role allows
- Full org — broadest view for workspace leaders
Employee hierarchy
A Digital Employee can delegate to other Digital Employees — a parent with subagents on the mesh, not a flat list. Practical limits you will hit in the product:- Delegation depth is shallow (a subagent cannot spawn its own subagents)
- Each orchestrator supports a bounded number of subagents
Manager and admin oversight
Workspace owners and people with manage access can configure employees they are allowed to see, pause or resume them, and adjust budgets and connectors. Run history and documents respect the same visibility: you only open drawers and files for employees in your allowed Layers view unless you have broader workspace oversight. Company Members and Permissions (outside Cowork) controls who can hire, invoke runs, view all employees, or read every document. Tess applies those rules automatically on the mesh — there is no second permission screen inside Cowork.To change who can hire, manage teams, or access features, use your workspace Members and Permissions settings in Tess.
Audit trail
Important actions — creating or pausing an employee, starting or completing runs, budget warnings, squad membership changes — are recorded in Tess’s activity log asynchronously. Admins use this for compliance and troubleshooting; day-to-day users feel it as reliable history in employee timelines and workspace audit exports when enabled.Tips
- Align Cowork Layers with your role before reviewing a teammate’s canvas in Follow mode
- Keep orchestrator teams small — delegation is powerful but adds monitoring surface
- Use Mission Control / Day Planner to catch pending approvals across everyone you manage