Governance - Enterprise - Docs - Kiro
https://kiro.dev/docs/enterprise/governance/ • 179 KB fetched Open original page
Governance - Enterprise - Docs - Kiro
Loading image... Product
* About Kiro
* IDE
* CLI
* Web
* Mobile
* Crew
* Pricing
* Downloads
For
* Enterprise
* Startups
* Students
Community
* Overview
* Ambassadors
* Discord
* Events
* Powers
* Shop
* Showcase
Resources
* Docs
* Blog
* Changelog
* FAQs
* Report a bug
* Suggest an idea
* Billing support
Social
*
*
*
*
*
*
*
English
Site Terms License Responsible AI Policy Legal Privacy Policy Cookie Preferences English
Loading image...
* Apps
* CLI
* Web
* Enterprise
* Pricing
* Docs
* Community
* Resources
SIGN IN DOWNLOADS
Loading image...
Get Started
Installation Authentication Your first project
Models
Overview Available models Reasoning effort
Features
How Kiro works Specs
Steering Hooks
MCP
Permissions Custom agents
Agent Skills Powers
Cloud sessions Compaction Kiroignore Checkpoints and rewind Built-in tools
Configuration scopes
IDE 1.x
What's new in 1.0
Setup & First Run Editor
Chat
Experimental
Troubleshooting 0.x reference
CLI
What's new in 3.0
Setup & First Run Terminal UI
Chat
Voice mode Headless mode ACP Auto complete Experimental
2.x reference
Crew
Quick start Installation Running 24/7 Chat
Agent Capabilities
Features
Interfaces
Apps
System & storage Configuration Security Troubleshooting
Web
Setup & First Run Identity Center Connect your repositories
Working with the agent
Autonomous mode Automations Memory Configuration Sync Sandbox
Mobile - Preview
Overview
Commands and Reference
CLI commands Slash commands Built-in tools Exit codes Settings
Billing
Overview Managing your subscription Upgrading your plan Downgrading your plan Cancelling your plan Purchasing add-on credits Managing your payments Managing usage notifications Managing your taxes Contacting billing support Deleting your account Related questions
Enterprise
Concepts Onboarding quickstart Connecting your identity provider
Deployment options Subscribe your team Manage subscriptions Governance
Permission policies
MCP
Models
API keys
Web tools
Monitor and track
Settings Managed updates Billing IAM Supported regions
Privacy and Security
Overview Data protection Code references Compliance validation Infrastructure security IAM permissions Firewalls, proxies, and data perimeters VPC endpoints (AWS PrivateLink)
Guides
Overview Language support
Learn by playing
Migration
Migrating from Q Developer Migrating from VSCode Upgrading from Q CLI
* Docs
*
* Enterprise
*
* Governance
Copy page View as Markdown
Governance
Copy page View as Markdown
As an administrator, you can control which models and MCP servers are available to your users. These governance controls are managed through the Kiro console under Settings > Shared settings .
Model governance
By default, users can access any model supported by Kiro. You can restrict this by toggling on model access management and selecting an approved list of models. You can also set a default model that is automatically applied to all clients.
For details, see Models .
MCP governance
By default, users can use any MCP server in their Kiro client. You can either disable MCP entirely or specify an allow-list of vetted MCP servers through an MCP registry. These policies can be set at the organization level or overridden per account.
For details, see MCP tools .
API key governance
By default, users cannot generate API keys to use with Kiro CLI. You can enable users to generate API keys.
For details, see API keys .
Web tools governance
By default, users can use the web_search and web_fetch tools to search the web and fetch content from URLs. You can disable web tools for all users in your account or organization.
For details, see Web tools .
Cloud sessions governance
For organizations using IAM Identity Center, Cloud Sessions are off by default. Administrators enable them from Settings > Kiro Settings by toggling on Cloud Sessions in the AWS account where the Kiro profile is configured.
This setting was previously labeled Kiro Web (Preview) . Organizations that already enabled it stay enabled, so they do not need to take action. For organizations setting up Kiro for the first time, Cloud Sessions stay disabled until an administrator opts in.
Every Kiro Web session now runs as a cloud session. Until Cloud Sessions are enabled, users cannot start sessions in Kiro Web. The same toggle also controls cloud sessions in Agent Focus Mode and the Kiro CLI with kiro-cli --cloud .
Cloud Sessions and API-key generation are independent controls. Enabling one does not enable the other. To control API-key generation, use the separate toggle described in API keys .
Some shared administrator settings, including MCP configuration, model availability, and Customer Managed Keys, do not apply to Kiro Web sessions. See Kiro Web with AWS Identity Center for the enablement steps, requirements, and the full list of settings that don't carry over.
Page updated: September 2, 2026
Manage subscriptions
Permission policies
Links found on this page
- About Kiro [direct]
- IDE [direct]
- CLI [direct]
- Web [direct]
- Mobile [direct]
- Crew [direct]
- Pricing [direct]
- Downloads [direct]
- Enterprise [direct]
- Startups [direct]
- Students [direct]
- Overview [direct]
- Ambassadors [direct]
- Discord [direct]
- Events [direct]
- Powers [direct]
- Shop [direct]
- Showcase [direct]
- Docs [direct]
- Blog [direct]
- Changelog [direct]
- FAQs [direct]
- Report a bug [direct]
- Suggest an idea [direct]
- Billing support [direct]
- Site Terms [direct]
- License [direct]
- Responsible AI Policy [direct]
- Legal [direct]
- Privacy Policy [direct]
- Cookie Preferences [direct]
- Loading image... [direct]
- SIGN IN [direct]
- Installation [direct]
- Authentication [direct]
- Your first project [direct]
- Overview [direct]
- Available models [direct]
- Reasoning effort [direct]
- How Kiro works [direct]
- Specs [direct]
- Steering [direct]
- Hooks [direct]
- MCP [direct]
- Permissions [direct]
- Custom agents [direct]
- Agent Skills [direct]
- Powers [direct]
- Cloud sessions [direct]
- Compaction [direct]
- Kiroignore [direct]
- Checkpoints and rewind [direct]
- Built-in tools [direct]
- Configuration scopes [direct]
- What's new in 1.0 [direct]
- Setup & First Run [direct]
- Editor [direct]
- Chat [direct]
- Experimental [direct]
- Troubleshooting [direct]
- 0.x reference [direct]
- What's new in 3.0 [direct]
- Setup & First Run [direct]
- Terminal UI [direct]
- Chat [direct]
- Voice mode [direct]
- Headless mode [direct]
- ACP [direct]
- Auto complete [direct]
- Experimental [direct]
- 2.x reference [direct]
- Quick start [direct]
- Installation [direct]
- Running 24/7 [direct]
- Chat [direct]
- Agent Capabilities [direct]
- Features [direct]
- Interfaces [direct]
- Apps [direct]
- System & storage [direct]
|
|