Acquia AI maintains a strict boundary
Governance rests on three core principles
Bounded capability set: The agent does not modify application code or infrastructure configurations
Scoped agent role: The agent holds a dedicated Agents Team role, separate from user roles, and never inherits permissions from the requesting user
Two-stage approval: The agent proposes a plan and takes no action without human approval
Performs no actions without approval
Does not modify application code or code repositories
Does not modify infrastructure configurations, such as cache clears, domain name record changes, or certificate installations
Takes no corrective action on a diagnosis
Does not block publication because of a low governance score
Does not perform continuous monitoring
Does not search logs independently
Cannot submit a support case
Does not resolve live outages or critical issues
External systems outside Acquia Cloud Platform, such as browser rendering, CDN behavior, and third-party scripts
Cron job diagnoses
Audit logs or user activity logs
Applications hosted outside Cloud Platform
Raw log content
No automatic reversal: A revert operation requires the same approval process as any other change
No activity record: No customer-visible record of agent activity is provided
No per-user capability limits: The agent role applies to the entire project, so every user with access can delegate the same set of tasks
Fixed Source CMS configuration: Source CMS provides no edits to the agent role or permission set
Global connector settings: Users with Administrator role can turn a connector on or off
Single-target operations: Tasks run on one site or one application at a time without batch actions across multiple sites
Acquia Source CMS restriction: Site work applies to Acquia Source CMS sites only
Connector limits: Slack serves as the sole connector
The agent returns matching assets with a preview, metadata, usage rights, and links, within the permissions a DAM administrator has granted. A user can also update assets.
Cannot search across two DAM accounts in a single request
Accesses the Assets application only, excluding Entries, Templates, and Workflow
Does not extend permissions beyond limits configured by a DAM administrator
Performs no SEO scans
Performs no data protection scans
Runs checks only on request, without automatic pre-publication checks
Fixes apply only to custom components on connected Acquia Source sites for a reviewed set of common accessibility errors
The agent holds a dedicated Agents Team role, separate from human user roles
Cloud Platform: An administrator configures exact permissions for the Agents Team role per environment
Source CMS: The agent holds a fixed member role that cannot change
Acquia DAM: A DAM administrator configures agent visibility scope directly inside Acquia DAM Admin Tools rather than Acquia AI
The agent holds permissions only on applications and sites assigned to the Agents Team
Organization structure: Organizations hold one project and one Agents Team
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Organization structure: Organizations hold one project and one Agents Team
If this content did not answer your questions, try searching or contacting our support team for further assistance.