What Architect can change

The full list of what Architect can read and edit, where each change lands, and which actions ask for your approval.

Overview

Architect’s capabilities come from a fixed set of tools. This page lists them by area, and for each area answers three questions:

  • What can Architect read?
  • What can it change, and where does the change land? Changes land in one of two places:
    • Draft: staged in your unpublished draft on a branch. Nothing reaches live callers until you publish the draft.
    • Workspace: applied immediately to a resource shared across the workspace, such as a tool or a knowledge base document.
  • Does it ask first? This column describes the default Approval required mode. In Auto-approve mode, Architect does not ask before any action. See Approval modes.

Every action also runs as you: Architect can only do what your own role allows. See Permissions, approvals, and drafts.

Agent configuration

AreaReadsChangesLands inAsks first
System prompt and first messageYesEdit, append, or rewriteDraftNo
Voice, LLM, language, turn-taking, and other agent settingsYes, including available LLMs and voicesAny setting in the agent’s configurationDraftNo
GuardrailsYesAdd, edit, or remove guardrailsDraftNo
Evaluation criteria and data collectionYesAdd, edit, or removeDraftNo
ProceduresYes, and searchCreate and edit. Procedures are compiled automatically after each change.DraftNo
DeleteDraftYes
WorkflowYesAdd, update, connect, and delete nodes and edgesDraftNo
Attached tools, knowledge base documents, and testsYesAttach or detachDraftNo
System tools, such as end call and transferYesEnable, disable, and configureDraftNo
DraftYes, including what differs from publishedDiscard the draftDraftYes
Publish—Cannot. Architect opens the publish dialog and you select Publish.

Workspace resources

AreaReadsChangesLands inAsks first
Webhook, client, and code toolsYes, including recent failures and dependentsCreate and update. Code tools require an Enterprise plan.WorkspaceYes
DeleteWorkspaceYes
MCP serversTools attached to the agentCannot create, edit, or delete——
Knowledge baseYes, including search and RAG queriesCreate a text or URL documentWorkspaceOnly if it goes in a folder or syncs automatically
Crawl a site, create folders, move items, rename or replace a documentWorkspaceYes
Index a document for RAGWorkspaceNo
Delete a document or folder—Cannot
Tests and simulationsYes, including runs, results, and failuresCreate LLM, tool-call, and simulation tests, or generate one from a real conversationWorkspace, attached through the draftNo
Update or delete a test, create a test folderWorkspaceYes
Run tests, including repeated runs to check for flakiness—No
VoicesYes, and searchAdd a voice to the workspaceWorkspaceNo
SecretsNames only, never valuesCannot create, edit, or delete——
Phone numbersYesPlace a test call through Twilio or SIPLive callYes
Buy, import, assign, or delete—Cannot
Channels, integrations, and triggersYesCannot change——

A test Architect creates exists in the workspace straight away, but it only joins the agent’s test suite when you publish the draft that attaches it. Architect can still run it before you publish.

Conversations, insights, and triage

AreaReadsChangesAsks first
Conversations and transcriptsList, count, filter, literal and semantic search, summaries, full detail, and in-depth analysis of individual conversationsCannot change—
Spotlight, topics, and insight reportsYes, including the values shown on dashboard chartsCan set dashboard filters on screenNo
Real-time alertsYesCannot change—
Triage ticketsYesCommentNo
Change status, for example to resolvedYes

Branches, proposals, and deployment

AreaReadsChangesAsks first
Branches and versionsYes, including history, diffs between versions, and merge previewsCreate a branchNo
Rename, archive, or change protectionYes
Merge one branch into anotherYes
Merge proposalsYesOpen a proposal and request reviewersNo
Approve, request changes, comment, merge, or closeCannot
Traffic splitYesChange the share of live traffic each branch receivesYes

Creating a branch or a merge proposal doesn’t change what live callers experience, so Architect doesn’t ask first. Merging into a branch that serves traffic, and changing the traffic split, both affect live callers immediately.

Agents

AreaReadsChangesAsks first
AgentsEvery agent you can accessCreate a new agent, or generate one from a descriptionNo
Create an agent from a templateYes
Archive an agentYes

Architect can’t permanently delete an agent. Its delete action archives the agent instead.

Interface actions

In addition to its agent-building tools, Architect can act on the page you are viewing: navigate to a page, highlight a control, fill in form fields, click buttons, and switch branches or dashboard filters. It uses these to walk you through the dashboard, for example when you ask how to invite a teammate. These actions don’t ask for approval. They can only do what you could do on that page yourself.

One agent or many

Architect isn’t limited to the agent you have open. It works on that agent by default, but it can read and edit any agent you have access to, and compare agents across the workspace. Open the workspace Architect page (Agents > Architect) for questions that span agents, such as “Which of my agents have no guardrails?”

When a single chat stages edits on more than one branch of an agent, Architect must say which branch each later edit is for.

What Architect cannot do

Architect has no tools for these actions:

  • Publish a draft. You always publish.
  • Approve, review, or merge a merge proposal.
  • Permanently delete an agent, a branch, a knowledge base document, a phone number, or a secret.
  • Create or edit MCP servers, secrets, integrations, channels, or alerts.
  • Buy, import, or assign phone numbers.
  • Read secret values.
  • Manage workspace members, roles, billing, or API keys through a dedicated tool. It can open those pages and walk you through them using the interface actions below.
  • Bypass your permissions. Architect is subject to every restriction on your account, including branch protection.