How to use Cowork

Runs a multi-step workspace task with tool calls, checkpoints and approval for risky actions.

What this section is for

Runs a multi-step workspace task with tool calls, checkpoints and approval for risky actions.

Before you start

You need access to IAM Agent, the correct tenant/workspace and permission to change this configuration. Prepare a non-sensitive example value such as Проверь тесты проекта и предложи минимальный план исправления без изменения файлов.

Buttons and forms

ControlWhat it does
RunRuns a check or dry run so the result can be reviewed before production use.
ApprovePerforms the action named in the interface. Review the resulting state or message before continuing.
RejectPerforms the action named in the interface. Review the resulting state or message before continuing.
PauseStops or pauses the current operation without deleting its configuration.
StopStops or pauses the current operation without deleting its configuration.

Primary path in the interface

  1. Open the application link above and sign in with the least-privileged role required for this section.
  2. Select the intended tenant or workspace. Do not continue while the header shows a different tenant.
  3. In the navigation, click Cowork. The expected address is https://agent.iamrouter.ru/cowork.
  4. Click Run. Enter the documented safe values: Проверь тесты проекта и предложи минимальный план исправления без изменения файлов. Do not paste a production secret into a free-text field.
  5. Review every field before the final Save, Run, Publish or Confirm action. If a preview or validation control exists, run it first.
  6. Review the validation message or changed row. The result must match this purpose: Runs a multi-step workspace task with tool calls, checkpoints and approval for risky actions.
  7. Only then continue to the next dependent section. Copy the request/correlation ID when the interface shows one.
  1. Open the deep link https://agent.iamrouter.ru/cowork instead of navigating through the sidebar.
  2. Confirm the tenant/workspace after the page loads; a deep link must not silently switch scope.
  3. Before automating the API path, run this product-specific read-only or validation command. It proves reachability but does not bypass application permissions:
iam-agent --help
iam-agent onboard
iam-agent capabilities

How to verify the result

The timeline contains the plan and tool results and write/execute actions do not run without approval.

If it did not work

SymptomWhat to do
401 / sign-in screenSign in again, then return to this page. Do not put a session token in a URL.
403Check the selected tenant and request the documented role; retrying with the same role will not help.
404Verify the exact path and whether the feature is enabled in this environment.
409Search for an object named Проверь тесты проекта и предложи минимальный план исправления без изменения файлов; continue with it or choose a unique name.
422 / validation errorCorrect only the highlighted fields. Keep identifiers lowercase unless the form explicitly allows otherwise.
429Wait for the displayed retry interval or reduce the request scope; do not start parallel retries.
5xx / timeoutRefresh once after the server has recovered; do not repeat a destructive action while its result is unknown. Save the correlation ID and timestamp for support.