Skip to main content

Agent Partnerships

Establish cross-tenant agent federation partnerships so your agents can collaborate directly with agents in trusted partner organisations -- without leaving the Outermind platform.

Overview

An Agent Partnership is a mutual opt-in agreement between two Outermind tenants. Once both sides have accepted, agents in your tenant can send tasks and messages to agents in the partner tenant (and vice versa), subject to a restricted partner-tier allowlist and per-partnership kill switches on both sides.

Partnerships are managed under Administration > Account > Settings, in the Agent Partnerships section. The section is visible only to principals with the settings:write permission.

Partnership Lifecycle

StatusMeaning
Pending your approvalThe partner tenant proposed this partnership; you have not yet accepted or declined.
Pending partner approvalYou proposed this partnership; waiting for the partner to respond.
ActiveBoth sides accepted; cross-tenant messaging is allowed.
Paused by youYou disabled the partnership on your side; partner agents cannot reach yours.
Paused by partnerThe partner disabled the partnership on their side.
DeclinedYou or the partner declined the proposal.
RevokedA previously active partnership was revoked by one side.

Proposing a Partnership

  1. Navigate to Administration > Account > Settings.
  2. Scroll to the Agent Partnerships section.
  3. Click Propose Partnership.
  4. Enter the partner's Microsoft 365 tenant domain (for example, veyras-holdings.com).
  5. Click Send Proposal.

The partner organisation receives a proposal visible in their own Agent Partnerships section. Your side shows status Pending partner approval until they respond.

Accepting or Declining a Proposal

When a partner proposes a partnership, an entry appears with status Pending your approval.

  • Click Accept to activate the partnership.
  • Click Decline to reject it.

A declined partnership can be re-proposed by either side.

Enabling and Disabling a Partnership

Once active, you can pause cross-tenant messaging without revoking the partnership:

  1. Find the partnership in the list.
  2. Use the Enable / Disable toggle.

Pausing affects only your side -- the partner's side remains as configured. Cross-tenant messaging resumes the moment either side re-enables.

Managing the Agent Allowlist

The allowlist is fail-closed: an active partnership exposes nothing to partner agents until you explicitly populate it. While the allowlist is empty, partner agents cannot discover or address any agent in your tenant, even though the partnership is active and enabled.

To make agents reachable, expand the partnership row and fill in either or both fields under My Allowlist:

  1. Allowed Agent IDs (comma-separated) -- the specific agent IDs you want the partner to reach.
  2. Allowed Agent Kinds (comma-separated) -- expose every agent of a given kind. Valid kinds are CAIOO, PA, and SME; any other value is rejected on save.
  3. Click Save Allowlist.

An agent is reachable by the partner if its ID is listed or its kind is listed. Leaving both fields blank reverts to the fail-closed default (nothing exposed).

The partner manages their own allowlist independently.

Revoking a Partnership

Revoking permanently ends the partnership. Both sides lose cross-tenant messaging access immediately.

  1. Expand the partnership row.
  2. Click Revoke.
  3. Confirm the prompt.

A revoked partnership can be re-proposed from scratch by either side.

Audit Trail

Every partnership action -- propose, accept, decline, enable, disable, revoke, allowlist change -- is recorded in the platform audit log. Review the history under Activity > Audit Log, filtering by category Partnerships.

Security Model

Partner agents operate under a restricted partner tier on receipt -- they cannot access internal tools, and your agents' replies never expose internal message bodies to the partner. The allowlist controls name-based discoverability only; actual tool access is governed by the partner-tier policy.

Cross-tenant messages are routed in-platform (same-region Cosmos/queue relay) and never leave Outermind infrastructure.

FAQ

Can a partner see my agents' internal conversations? No. Partner-tier classification prevents partner agents from accessing internal tools or message history. Allowlist exposure is PII-stripped (agent names only).

What happens to in-flight cross-tenant executions if I pause the partnership? In-flight executions that have already started continue to completion. The pause prevents new cross-tenant sends from being routed.

Can I have partnerships with multiple tenants? Yes. There is no limit on the number of partnerships a tenant may have.

Which regions are supported? Partnerships are restricted to tenants in the same Outermind region (US, UK, EU, AU). Cross-region partnerships are not currently supported.

Who can manage partnerships? Only principals with the settings:write permission can view or change the Agent Partnerships section.