ClickUp · ClickUp Brain AI

Super Agents

Configurable ClickUp Brain AI agents that run multi-step work across a Workspace after manual, scheduled or Automation triggers, using configured instructions, Skills, knowledge, memory and tools that create and modify persistent ClickUp objects and, where integrated tools are added, act in connected external services.

Recorded characteristics

Function
ClickUp documents Super Agents as Brain AI-powered teammates that perform multi-step workflows across the Workspace. A Super Agent is created through a natural-language Super Agent Builder, from the Super Agent catalog, from scratch in the AI Hub, or by asking Brain, and is configured from its profile in five sections: Instructions & Skills (always required; the AI model is selected here), Triggers, Tools, Knowledge and Memory. At runtime a trigger starts the Agent, which follows its primary instructions plus any trigger-specific additional instructions, draws on selected knowledge and activated memory, and runs the tools added to its profile. Super Agent Activity records each run with the tools that were run and, for some actions, the Agent's own explanation of what it did. ClickUp states that if a Super Agent does not have a given toolset, for example the Docs toolset, it cannot perform the corresponding actions.
Data access
ClickUp states that Super Agents are required to have access to all public locations and items in the Workspace and automatically receive public Workspace data as it is added. Beyond that, the builder explicitly selects knowledge: Workspace locations and items, certain connected apps, ClickUp's public help articles, and the web. ClickUp states that when a Super Agent is triggered in a private location that was not selected in its knowledge, it has temporary access to that location's data for the duration of that interaction only, while selecting a location in knowledge or granting access in instructions gives persistent access. ClickUp states that if private or external data is shared with a Super Agent, including Personal Lists, the Agent can use that data when responding to anyone who has permission to trigger the Agent, even if they do not have direct access to that data, and that a warning is shown when configuring an Agent where such privacy exposure exists. Adding personal app knowledge or personal-connection tools exposes that connected app's data to anyone who can interact with the Agent.
Actions
Can take actions
External actions
Conditional
Human confirmation
Conditional
Permission basis
Mixed
Administrative control
ClickUp documents that the AI ClickApp must be activated for the Workspace, and the Chat ClickApp for Chat interaction. Anyone with Can manage permission can edit an Agent's configuration, including instructions, triggers, tools, knowledge and memory; users without Can manage see only the avatar and not instructions, triggers, tools or knowledge. Agents can be made private, visible only to their creator, or shared with individual users or Teams, and an Agent has a primary owner (its creator, listed as manager). Individual triggers are activated or deactivated by toggle, scheduled triggers are added and deleted individually, and the whole Agent is activated or deactivated in the Workspace. Business Plus and Enterprise Workspaces have a Custom Role Permission that prevents members and admins from creating Super Agents, and editing Super Agent permissions requires a paid plan. The Workspace audit log includes a dedicated Agents log, and Super Agent Activity plus Super Credit usage views are available in the AI Hub Analytics.
Default state
Disabled
Availability
ClickUp documents availability and limits varying by plan and user role. By default members, admins and owners can create, trigger, manage and interact with all public Super Agents; guests, view-only guests, permission-controlled guests, limited members and view-only limited members cannot see Super Agent profiles or create or trigger a Super Agent, although in locations they can access they can see Super Agent comments, generated content and avatars. ClickUp states that all plans get a trial of select Brain AI features and that after that only paid plans can purchase Brain AI add-ons, and that editing Super Agent permissions requires a paid plan. Super Agents are also documented on the mobile app and the Brain MAX mobile app.
Licensing
ClickUp documents that Super Agent runs consume Super Credits and that Super Credit usage for Super Agents can be viewed from the AI Hub. Brain AI features are subject to ClickUp's fair use policy, and ClickUp states that future restrictions may apply and usage limits may change. For a limited time all plans can connect external MCP servers, with pricing subject to change.
External model or provider
ClickUp documents that Max is the default model, that other premium AI models are offered, and that the model is selected in the Super Agent's Instructions section or from the model control in the Agent profile, where the default shown is Auto. A Super Agent reply can be retried with a different model. ClickUp does not enumerate the selectable Super Agent model versions in this documentation, so no specific external model versions are recorded here.
Limitations and uncertainty
Human approval is not universal. ClickUp's overview states Super Agents "seek human approval for critical decisions", but the permissions article states that if you want a Super Agent to check with a person before taking action you configure that in the Agent's instructions or preferences, and Super Agent Activity documents scheduled runs that show no Run By user; documented automatic approval is limited to the Agent asking before storing a Preferences memory. No documented list of actions that always require approval exists, so human confirmation is recorded as conditional. Permission basis is recorded as mixed: ClickUp states Super Agents "are treated as ClickUp users" with required access to all public Workspace locations, per-Agent Can trigger and Can manage permissions, and external tools running through personal or Workspace app connections, and ClickUp explicitly documents responses using data the triggering user cannot access directly; this is not a plain inheritance of the triggering user's permissions, and ClickUp does not describe an independent agent security principal beyond being treated as a user. Orchestration internals are not documented: ClickUp describes multi-step workflows, multi-step reasoning and learning from errors and feedback, and Activity shows which tools ran and when, but branching, retry logic and dynamic tool-selection mechanics are not specified. Failure handling is documented only at run level, where one failed step fails the whole run. Activity history retention is not documented and Activity is not an immutable audit log; the Agents audit log records configuration events, not every Agent action, though actions taken by Super Agents are included in the Task, Fields and Hierarchy logs. Authority documented for Autopilot Agents, Brain direct interaction, Brain MAX, the ClickUp MCP Server and AI Fields is excluded from this record.

Evidence