What policies control
Current desktop policy keys map to concrete product capabilities:Custom providers: allow or block locally added model providers that were not deployed through OpenWork Cloud.Enable OpenCode Zen Models: allow or block built-in OpenCode models.Multiple workspaces: allow or block creating or configuring more than one local workspace.Control Settings: allow or block desktop settings. When blocked, the desktop app hides every settings page except the Cloud account page, and hides the settings shortcuts in the command palette and account menu. Members can still see their account, switch organizations, and log out.Manage Extensions: allow or block installing and managing local extensions and MCP servers. When blocked, the Library hides the workspace MCP and GitHub import flows and marks third-party directory entries asDisabled by organization; organization-approved skills, connections, and built-in OpenWork extensions still work.Built-in Extensions: allow or block OpenWork-provided built-in extensions, including browser, image, and local-provider extensions.Alpha updates: allow or block opting into experimental Alpha desktop updates.Welcome Page: show or hide the getting-started page for new users.
Restricted mode
Every policy has a mode selector at the top of its editor:Customlets you choose each capability.Restrictedgives members a vanilla OpenWork: they can chat and use organization-approved skills, but cannot change desktop settings, add providers or use models outside the organization, add workspaces, use built-in extensions, install extensions or MCP servers, or opt into Alpha updates. The locked capabilities stay off until you switch the policy back toCustom. TheWelcome Pagepreference stays editable in both modes.
Restricted to the default policy to lock members down. A targeted policy in Restricted mode grants nothing on its own.
Configure a policy
- Open app.openworklabs.com and choose your organization.
- Go to
Desktop policies. - Create a new policy or edit the default policy.
- Pick
Restricted, or stay inCustomand turn capabilities on or off. - Assign the policy to members or teams when it should not apply to everyone.
- Save the policy, then have members reload, refresh their Cloud account, switch the active organization, or wait for the hourly desktop-config refresh.
Disabled by organization explanation, and the account page lists effective capabilities in its App permissions tab.