Secrets and variables
Bringing your own model keys, and the organization variables agents write into their instructions.
Two different things share this screen.
Bring your own keys
You can run agents on your own model access rather than the platform's. A configuration holds the provider, the model, a base address where the service is not at its default, and the key itself. Keys are stored write-only: once saved, the value is masked and can be replaced but not read back.
Saved configurations then appear as an option in an agent's model setting, alongside the platform models. See Agents.
This is the route for organizations that need model usage on their own account for billing, contractual or data-residency reasons.
Variables
Variables are named values for the organization, each a key and a value. Their purpose is to be referenced from an agent's instructions: the canvas has a picker that inserts them into the text.
That indirection is the point. A phone number, a returns window or a support address maintained here is correct in every agent that references it, and changing it once changes it everywhere, rather than requiring you to find every agent that mentions it.
Who can see this
This screen is administration. Members with the user role do not have it in their sidebar.