Skip to main content
Settings → Agents shapes how every agent in the workspace triages. It opens on the system prompt, so you can see what agents are told before you change anything.
The page has four sections, each linked from the settings sidebar under Agents: Changes take effect on the next agent run. Drafts are kept when you switch between sections.

System prompt

The default prompt Clarion gives every triage agent in the workspace. Clarion maintains it and you can’t edit it; the version shown next to it changes whenever Clarion updates the prompt. What you can change is added on top of it: Agent behavior and Escalation & notifications. The escalation bar is written into the prompt itself, so the text you see reflects your current setting. Skills are not part of the prompt. Each agent sees the list of skills assigned to it and opens one only when an issue calls for it, so skills shape how agents work without making every triage longer.

Agent behavior

Standing instructions every agent run inherits, on top of whatever its skills say. These were previously called workspace instructions and lived under Settings → Workspace. Over MCP, read and replace them with get_agent_behavior and set_agent_behavior. Use them for context that doesn’t belong to any single skill:
  • Your business context, and who owns which system.
  • Organization-wide terminology, escalation hierarchy, and on-call conventions.
  • Environment-specific quirks (“staging fires this alert nightly; it is expected”).
  • What agents must never do.
Notification channels do not belong here. Configure them under Escalation & notifications; agents read that set directly and pick a destination per run. The editor supports the same @-references as the skill editor, so instructions can point at a specific skill by name.
Keep instructions short and high-signal. They are added to every run and compete with skill content for the agent’s attention. If guidance only applies to one class of issue, it belongs in a skill, not here.

Escalation and notifications

Decides when an agent pages your team, and where it sends escalations, approval requests and questions. Destinations, routing and the on-call rotation are covered in Notifications.

Severities that escalate

When an agent finishes triaging an issue it considers a real problem, it escalates it: the issue moves to Escalated and the team is paged. This setting is the bar for that page. The agent escalates only when the issue’s severity is one you selected. Anything below the bar moves to Open instead, so it still waits for a human, just without a notification.
  • Default: High and Critical.
  • Choices: any combination of Low, Medium, High, and Critical.
  • Minimum: at least one severity. The last one can’t be unchecked.
A few things are worth knowing:
  • The bar applies to agents only. A member who clicks Escalate on an issue always escalates it, whatever its severity.
  • Parking an issue in Open doesn’t change the verdict. Its disposition and severity stay as triage set them; only the status differs.
  • Some issue kinds are stricter. Issues of kind Risk or Vulnerability stay Open on an agent’s decision regardless of this setting. The one exception is a Critical finding the agent justifies as imminent danger. See Issue kinds.
  • Agents are told the bar. Your selection is written into the system prompt, so the agent works from your policy rather than the default.
Don’t restate or override the escalation bar in skills or agent behavior, for example “escalate every Medium finding”. An instruction that conflicts with the system prompt confuses the agent, and the setting still decides the final status. To change which severities escalate, change this setting.
Adding Medium pages more often and catches more. Narrowing to Critical alone keeps pages rare but leaves more for your team to sweep in the Open queue. Start from the default and adjust once you see your volume.

Skills

Step-by-step playbooks agents open on demand for specific kinds of alerts, such as a phishing report or a suspicious sign-in. Each row shows the skill’s description, which is the only text an agent uses to decide whether to open it; missing descriptions and broken references are flagged. See Skills and Authoring best practices.

Workspace

Domains, human-input and Teams scoping toggles, and BYOK.

Notifications

Destinations, routing, and the on-call rotation.