> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tess.im/llms.txt
> Use this file to discover all available pages before exploring further.

# Governance

> Who sees which employees on the mesh, manager hierarchy, and oversight on Cowork

## Overview

As Digital Employees spread across a workspace, governance answers: **who can see and manage whom**, **how delegation hierarchies appear on the mesh**, and **what evidence exists when something changes**.

Cowork surfaces governance through the **Mesh Canvas**, **Cowork Layers**, and employee drawers — not through a separate admin console inside Cowork.

## What you see on the mesh

### Cowork Layers

The **Cowork Layers** control (action bar on Mission Control) filters whose employees appear on your canvas:

* **My area** — employees you own
* **Direct reports** — employees owned by people who report to you (when you are a manager)
* **Their employees** — extend down the org tree as your role allows
* **Full org** — broadest view for workspace leaders

If you and a colleague see different nodes, check Layers before assuming an employee is missing.

### Employee hierarchy

A Digital Employee can **delegate** to other Digital Employees — a parent with subagents on the mesh, not a flat list.

Practical limits you will hit in the product:

* Delegation depth is shallow (a subagent cannot spawn its own subagents)
* Each orchestrator supports a bounded number of subagents

When a parent delegates, it may open a **live sync** with the child instead of a one-shot handoff. See [Real-time collaboration](/en/cowork/colaboracao-tempo-real/realtime-collaboration).

Subagents appear nested under their parent in views that show hierarchy; open each node’s drawer for its own runs and files.

## Manager and admin oversight

**Workspace owners** and people with **manage** access can configure employees they are allowed to see, pause or resume them, and adjust budgets and connectors.

**Run history and documents** respect the same visibility: you only open drawers and files for employees in your allowed Layers view unless you have broader workspace oversight.

Company **Members and Permissions** (outside Cowork) controls who can hire, invoke runs, view all employees, or read every document. Tess applies those rules automatically on the mesh — there is no second permission screen inside Cowork.

<Info>
  To change who can hire, manage teams, or access features, use your workspace **Members and Permissions** settings in Tess.
</Info>

## Audit trail

Important actions — creating or pausing an employee, starting or completing runs, budget warnings, squad membership changes — are recorded in Tess’s **activity log** asynchronously. Admins use this for compliance and troubleshooting; day-to-day users feel it as reliable history in employee timelines and workspace audit exports when enabled.

## Tips

* Align **Cowork Layers** with your role before reviewing a teammate’s canvas in **Follow** mode
* Keep orchestrator teams small — delegation is powerful but adds monitoring surface
* Use **Mission Control / Day Planner** to catch pending approvals across everyone you manage

## Next steps

* [Mission Control monitoring](/en/cowork/digital-employees/monitor-dashboard/monitor-dashboard)
* [Real-time collaboration](/en/cowork/colaboracao-tempo-real/realtime-collaboration)
* [Detailed configuration](/en/cowork/digital-employees/configuracao-detalhada/detailed-configuration)

## Other languages

* [Português (BR)](/pt/cowork/digital-employees/governanca/governanca)
* [Español](/es/cowork/digital-employees/governanca/gobernanza)
