SOLFIND
Web Lens
Portal home

Governance - Enterprise - Docs - Kiro

https://kiro.dev/docs/enterprise/governance/ • 179 KB fetched
Open original page


Governance - Enterprise - Docs - Kiro Loading image... Product * About Kiro * IDE * CLI * Web * Mobile * Crew * Pricing * Downloads For * Enterprise * Startups * Students Community * Overview * Ambassadors * Discord * Events * Powers * Shop * Showcase Resources * Docs * Blog * Changelog * FAQs * Report a bug * Suggest an idea * Billing support Social * * * * * * * English Site Terms License Responsible AI Policy Legal Privacy Policy Cookie Preferences English Loading image... * Apps * CLI * Web * Enterprise * Pricing * Docs * Community * Resources SIGN IN DOWNLOADS Loading image... Get Started Installation Authentication Your first project Models Overview Available models Reasoning effort Features How Kiro works Specs Steering Hooks MCP Permissions Custom agents Agent Skills Powers Cloud sessions Compaction Kiroignore Checkpoints and rewind Built-in tools Configuration scopes IDE 1.x What's new in 1.0 Setup & First Run Editor Chat Experimental Troubleshooting 0.x reference CLI What's new in 3.0 Setup & First Run Terminal UI Chat Voice mode Headless mode ACP Auto complete Experimental 2.x reference Crew Quick start Installation Running 24/7 Chat Agent Capabilities Features Interfaces Apps System & storage Configuration Security Troubleshooting Web Setup & First Run Identity Center Connect your repositories Working with the agent Autonomous mode Automations Memory Configuration Sync Sandbox Mobile - Preview Overview Commands and Reference CLI commands Slash commands Built-in tools Exit codes Settings Billing Overview Managing your subscription Upgrading your plan Downgrading your plan Cancelling your plan Purchasing add-on credits Managing your payments Managing usage notifications Managing your taxes Contacting billing support Deleting your account Related questions Enterprise Concepts Onboarding quickstart Connecting your identity provider Deployment options Subscribe your team Manage subscriptions Governance Permission policies MCP Models API keys Web tools Monitor and track Settings Managed updates Billing IAM Supported regions Privacy and Security Overview Data protection Code references Compliance validation Infrastructure security IAM permissions Firewalls, proxies, and data perimeters VPC endpoints (AWS PrivateLink) Guides Overview Language support Learn by playing Migration Migrating from Q Developer Migrating from VSCode Upgrading from Q CLI * Docs * * Enterprise * * Governance Copy page View as Markdown Governance Copy page View as Markdown As an administrator, you can control which models and MCP servers are available to your users. These governance controls are managed through the Kiro console under Settings > Shared settings . Model governance By default, users can access any model supported by Kiro. You can restrict this by toggling on model access management and selecting an approved list of models. You can also set a default model that is automatically applied to all clients. For details, see Models . MCP governance By default, users can use any MCP server in their Kiro client. You can either disable MCP entirely or specify an allow-list of vetted MCP servers through an MCP registry. These policies can be set at the organization level or overridden per account. For details, see MCP tools . API key governance By default, users cannot generate API keys to use with Kiro CLI. You can enable users to generate API keys. For details, see API keys . Web tools governance By default, users can use the web_search and web_fetch tools to search the web and fetch content from URLs. You can disable web tools for all users in your account or organization. For details, see Web tools . Cloud sessions governance For organizations using IAM Identity Center, Cloud Sessions are off by default. Administrators enable them from Settings > Kiro Settings by toggling on Cloud Sessions in the AWS account where the Kiro profile is configured. This setting was previously labeled Kiro Web (Preview) . Organizations that already enabled it stay enabled, so they do not need to take action. For organizations setting up Kiro for the first time, Cloud Sessions stay disabled until an administrator opts in. Every Kiro Web session now runs as a cloud session. Until Cloud Sessions are enabled, users cannot start sessions in Kiro Web. The same toggle also controls cloud sessions in Agent Focus Mode and the Kiro CLI with kiro-cli --cloud . Cloud Sessions and API-key generation are independent controls. Enabling one does not enable the other. To control API-key generation, use the separate toggle described in API keys . Some shared administrator settings, including MCP configuration, model availability, and Customer Managed Keys, do not apply to Kiro Web sessions. See Kiro Web with AWS Identity Center for the enablement steps, requirements, and the full list of settings that don't carry over. Page updated: September 2, 2026 Manage subscriptions Permission policies

Links found on this page

  1. About Kiro [direct]
  2. IDE [direct]
  3. CLI [direct]
  4. Web [direct]
  5. Mobile [direct]
  6. Crew [direct]
  7. Pricing [direct]
  8. Downloads [direct]
  9. Enterprise [direct]
  10. Startups [direct]
  11. Students [direct]
  12. Overview [direct]
  13. Ambassadors [direct]
  14. Discord [direct]
  15. Events [direct]
  16. Powers [direct]
  17. Shop [direct]
  18. Showcase [direct]
  19. Docs [direct]
  20. Blog [direct]
  21. Changelog [direct]
  22. FAQs [direct]
  23. Report a bug [direct]
  24. Suggest an idea [direct]
  25. Billing support [direct]
  26. Site Terms [direct]
  27. License [direct]
  28. Responsible AI Policy [direct]
  29. Legal [direct]
  30. Privacy Policy [direct]
  31. Cookie Preferences [direct]
  32. Loading image... [direct]
  33. SIGN IN [direct]
  34. Installation [direct]
  35. Authentication [direct]
  36. Your first project [direct]
  37. Overview [direct]
  38. Available models [direct]
  39. Reasoning effort [direct]
  40. How Kiro works [direct]
  41. Specs [direct]
  42. Steering [direct]
  43. Hooks [direct]
  44. MCP [direct]
  45. Permissions [direct]
  46. Custom agents [direct]
  47. Agent Skills [direct]
  48. Powers [direct]
  49. Cloud sessions [direct]
  50. Compaction [direct]
  51. Kiroignore [direct]
  52. Checkpoints and rewind [direct]
  53. Built-in tools [direct]
  54. Configuration scopes [direct]
  55. What's new in 1.0 [direct]
  56. Setup & First Run [direct]
  57. Editor [direct]
  58. Chat [direct]
  59. Experimental [direct]
  60. Troubleshooting [direct]
  61. 0.x reference [direct]
  62. What's new in 3.0 [direct]
  63. Setup & First Run [direct]
  64. Terminal UI [direct]
  65. Chat [direct]
  66. Voice mode [direct]
  67. Headless mode [direct]
  68. ACP [direct]
  69. Auto complete [direct]
  70. Experimental [direct]
  71. 2.x reference [direct]
  72. Quick start [direct]
  73. Installation [direct]
  74. Running 24/7 [direct]
  75. Chat [direct]
  76. Agent Capabilities [direct]
  77. Features [direct]
  78. Interfaces [direct]
  79. Apps [direct]
  80. System & storage [direct]