Notion announced model controls on 9 September, giving workspace owners separate choices for the models available to Notion Agent and Custom Agents. The dated release note also introduces a default-model setting for Custom Agents and identifies Business and Enterprise as the supported plans.
The change addresses a practical issue in shared AI workspaces: an individual’s preferred model is not necessarily the organisation’s approved model for every task. Administration now needs to cover both interactive use and the agents configured to perform recurring work. Those two categories can have different cost, access and review requirements.
Availability and spending are separate choices
Notion’s model and credit controls guide says premium models for Notion Agent remain off until an owner or administrator enables them. Using them spends Notion credits. The guide describes per-person and group credit limits, a workspace default and a dashboard showing member spending.
Crucially, those switches do not change the models available to Custom Agents. Their controls and model picker are separate. An administrator who disables a model for personal use should therefore not assume the same decision has automatically been applied to every configured agent.
The distinction gives teams a clearer vocabulary for rollout decisions. Approving a model answers whether it can be selected. Setting a credit limit answers how much a person or group can spend through the relevant mechanism. Neither decision, on its own, defines which documents an agent may read or which actions it may perform.
Included usage is not an unlimited budget
The separate usage allowance documentation describes six-hour and monthly windows for certain AI features. Premium models spend credits outside that allowance. Custom Agents and Workers also use credits rather than the personal-agent allowance. Administrators can decide whether members who exhaust their allowance may continue by spending credits.
This matters when interpreting a usage dashboard. A user may have ordinary allowance remaining while a premium-model task still incurs credit consumption. Conversely, a temporary limit on one feature does not mean all AI-related activity in the workspace has stopped. The source documentation treats these as different mechanisms, and internal guidance should do the same.
For a pilot, record which mechanism each workflow uses. A simple task catalogue can identify the owner, selected model and relevant spending control. That makes a surprising bill easier to investigate without relying on a vague instruction to use AI less.
A model allowlist is not a data-access policy
Notion’s Custom Agents security guide warns that those agents have independent permissions. Someone using an agent can potentially receive information through it that they could not access directly. The guide describes warnings when sharing sensitive resources and restrictions on who can expand third-party connections.
It also explains that connected resources need an agent editor with access; an agent stops running if all editors lose access to a resource. Users with interaction permission can inspect the agent’s settings without necessarily being allowed to change them. These controls are relevant background when deciding which models to permit, but they are not newly announced by the short September release note.
The practical implication is that model selection and resource sharing should be reviewed together. An approved model cannot compensate for an agent being given a broader collection of material than its audience should receive. Review the agent’s purpose and intended users before deciding that its configuration is appropriate.
Privacy settings still need their own review
The broader Notion AI privacy documentation says customer data is not used for model training by default and describes different retention arrangements for Enterprise and other workspaces. It also identifies exceptions for some data-retaining features and distinct practices for External Agents. These are platform-level statements, not a guarantee that every combination of feature and configuration has identical data handling.
That is why an organisation should avoid reducing its policy to a list of model names. The feature, connected resources and relevant settings also matter. A useful approval record should state what was reviewed and for which workflow, rather than imply blanket permission for all future uses of the same model.
Test the administrative outcome
Our assessment is that the release makes governance more concrete, provided teams test the resulting experience. After changing a setting, check what an ordinary member can select and what a Custom Agent actually uses. Do not rely solely on the owner’s view of the settings screen.
A small rollout can include one routine workflow and one task that genuinely benefits from a more capable model. Compare output quality, review effort and credit consumption over several runs. Keep the same acceptance criteria for both, so a lower price is not mistaken for better value when staff must repeatedly repair the result.
Notion’s model controls are a useful administrative addition, not a substitute for workflow ownership. Their value will come from turning an organisation’s decisions into consistent behaviour across personal and custom agents, with spending and resource access checked alongside model availability.