Dokki Blog logo

What Are Notion Agents? Personal vs Custom Agents

Notion Agents are AI teammates inside Notion. The name covers two different operating models: the personal Notion Agent works on demand with the same permissions as the person using it, while Custom Agents are specialized team agents with their own explicitly granted access, triggers, sharing settings, activity history, and usage costs.

Understanding that distinction is essential. It determines what the agent can see, who benefits from its access, when it runs, how it is governed, and how much it costs.

Permission-principal comparison between the personal Notion Agent and a Custom Agent

Personal Agents inherit the current user's access; Custom Agents use their own explicitly granted scope.

The short answer

Use the personal Notion Agent for interactive work you initiate: researching across accessible workspace and connected content, creating or editing pages and databases, transforming files, and completing multi-step tasks in a chat.

Use a Custom Agent for recurring or event-driven work owned by a team: triaging requests, producing scheduled reports, maintaining knowledge, updating records, or responding to Notion and Slack events.

The permission boundary is different:

  • A personal Notion Agent acts as you. It sees and edits only what your user account can see and edit.

  • A Custom Agent acts as a specialized team member. It has access to the specific pages, databases, and connected apps granted to the agent, and that access can differ from the access of a person interacting with it.

Custom Agents are available on Business and Enterprise plans and use Notion credits. They can continue running in the background after they are published.

What is the personal Notion Agent?

The personal Notion Agent is an interactive AI teammate inside the Notion interface. A person opens the Agent, asks for work, selects relevant sources, reviews the result, and continues the conversation.

According to Notion's current documentation, the Agent can use workspace context and connected apps to:

  • Search for knowledge and answer questions.

  • Create and edit pages.

  • Create and edit databases, views, forms, properties, and relations.

  • Read comments and search version history.

  • Ingest files such as PDFs and CSVs.

  • Turn unstructured input into structured pages or databases.

  • Complete multi-step tasks using the page, selected blocks, mentioned pages, people, or selected sources as context.

The defining characteristic is not the length of the task. It is the operating mode: a person invokes the Agent and the Agent acts under that person's permissions.

Personal Agent permission model

Notion states that the personal Agent has the same permissions as the user. If the user cannot view or edit a resource, the Agent cannot view or edit it either.

This makes the personal Agent intuitive for individual work. A user does not need to design a separate service identity before asking for help. The limitation is equally important: the Agent cannot become a shared cross-permission bridge simply because another team member needs an answer.

Best use cases

The personal Agent is a good fit for:

  • Synthesizing a project status from pages and databases the user can access.

  • Drafting an operating procedure from runbooks, incidents, and release notes.

  • Building a launch database from a product brief.

  • Turning a CSV into a structured database.

  • Editing a page against a style guide.

  • Researching connected sources and producing a cited brief.

The person remains the initiator and permission principal.

What is a Notion Custom Agent?

A Custom Agent is a reusable, specialized agent configured inside Notion. It has instructions, a model choice, tools and access, triggers, sharing permissions, activity history, and ownership.

Unlike the personal Agent, a Custom Agent can run automatically in the background. Notion documents recurring schedules, events in Notion, and events in Slack as trigger sources.

A Custom Agent can:

  • Read explicitly granted Notion pages and databases.

  • Use selected connected apps.

  • Monitor specified events.

  • Post reports or messages.

  • File bugs.

  • Update records.

  • Respond to comments, database changes, or Slack activity.

  • Continue running after it is published.

The agent becomes an operational object that a team can configure, share, monitor, duplicate, and transfer.

Personal vs Custom Agents

Question

Personal Notion Agent

Notion Custom Agent

Who starts the work?

A person, on demand

A person or configured trigger

Permission principal

The current user

The agent's explicitly granted access

Primary ownership

Individual user experience

Named agent owner and team sharing

Runs in background

Not as the core operating model

Yes, after publication

Trigger types

Interactive prompt and context

Schedule, Notion events, Slack events

Typical output

A page, database, answer, or edit for the user

Repeated reports, routing, updates, and messages

Sharing model

Follows the user's workspace access

Full access, edit, or interaction permissions on the agent

Governance

User permissions and workspace AI settings

Agent directory, activity, version history, controls, and Enterprise audit

Cost model

Depends on plan and AI availability

Business/Enterprise plus Notion credit usage

Best for

Ad hoc knowledge and creation work

Reusable team automation

The decision is not “simple task versus complex task.” A personal Agent can perform multi-step work. The decision is whether the job should be initiated by one person under personal permissions or should exist as a governed team process with its own access and triggers.

How Custom Agent permissions work

Custom Agent security involves two different permission questions.

1. What can the agent access?

The owner grants specific pages, databases, and connected applications through the agent's tools and access settings. Notion says Custom Agents do not receive full workspace access by default.

This scope determines the source material the agent can use and the resources it can modify.

2. Who can use or manage the agent?

The agent itself is shared with people, groups, or the workspace. Permission levels determine who can change instructions and access, inspect activity, run the agent, or interact with it.

These two permission layers work together. A user may be allowed to interact with an agent whose underlying resource access is different from the user's direct access.

The cross-permission risk buyers must understand

Notion explicitly documents that a Custom Agent can access a resource that the person interacting with it cannot see directly. The person sees only information the agent includes in its response.

That behavior enables cross-functional workflows, but it also creates a security review requirement. If a private page is removed from a user's direct access while the user can still interact with an agent that can read it, the agent can remain an indirect path to information from the page.

Controls should therefore evaluate:

  • The agent's resource scope.

  • The users and groups allowed to interact with the agent.

  • Whether outputs can contain sensitive details.

  • Which Slack channels the agent can read or write.

  • Activity history and Enterprise audit events.

  • Ownership continuity when the creator leaves.

Removing a resource from the agent's access takes effect immediately. Page and database owners can also remove a Custom Agent through the resource share menu.

What triggers can Custom Agents use?

Notion currently documents three trigger families.

Recurring schedules

A Custom Agent can run on a daily, weekly, monthly, yearly, or other configured cadence with a specified time and timezone.

Useful jobs include:

  • Weekly project summaries.

  • Daily support or sales briefs.

  • Monthly knowledge reviews.

  • Scheduled risk or backlog reports.

Notion events

A Custom Agent can react when:

  • A comment is added to a page.

  • A page is added to a database.

  • A database property is updated.

  • A page is removed from a database.

Some triggers support filters, such as a property value or database view. Filters matter because an unfiltered event stream can create noise and unnecessary credit consumption.

Slack events

After the Slack workspace and relevant channels are authorized, a Custom Agent can watch for:

  • A new channel message.

  • An emoji reaction.

  • A mention of the agent.

  • Optionally, thread replies.

The agent can read selected channels and post only to channels configured for the integration. Private-channel access requires explicit authorization.

How much do Notion Custom Agents cost?

Custom Agents require a Business or Enterprise plan and use Notion credits. Credit consumption varies with the model, the number of steps, source retrieval, tool use, and run frequency.

Notion's official examples currently estimate:

Workflow

Approximate cost per run

Q&A agent

$0.03–$0.11

Task routing agent

$0.05–$0.15

Status update agent

$0.08–$0.18

Mail triage agent

$0.04–$0.10

Daily brief agent

$0.10–$0.30

These are planning ranges, not fixed prices. The most reliable forecast comes from running the actual workflow, observing exact usage in the credits dashboard, and measuring at least one full operating cycle.

Use this formula:

Monthly agent cost = average cost per run × expected runs per month

Then test the sensitivity:

  • What happens when the trigger volume doubles?

  • How many external calls occur in one run?

  • Does the agent retry failed steps?

  • Which model is selected?

  • Does the agent run when a filter would have skipped the event?

  • Will the agent pause if the workspace runs out of credits?

A useful agent budget is tied to completed business outcomes, not just run count.

Custom Agent control loop from trigger and scoped access through action, review, and cost

A production Custom Agent is a feedback loop: every observed run should refine filters, scope, instructions, model choice, and budget.

How to design a reliable Custom Agent

A Custom Agent should be designed like an operating procedure, not a personality prompt.

Define one job and one outcome

Write the job in operational language:

  • “Every weekday at 4 PM, summarize changes to active launch risks and post a review-ready update.”

  • “When a new support escalation enters the database, classify severity, identify the owner, and create a response checklist.”

Avoid instructions such as “help the team with projects.” They provide no reliable completion condition.

Name the inputs

Specify which pages, databases, properties, views, or Slack channels are authoritative. If multiple sources conflict, define which source wins or require a human decision.

Define the output schema

Specify required fields, status values, evidence links, owners, and where the result is written. A repeatable output is easier to review and measure than free-form prose.

Constrain actions

Separate read-only analysis from write operations. For sensitive changes, require the agent to propose an update for review rather than execute automatically.

Configure narrow triggers

Use filters to reduce irrelevant runs. A support agent should not process every database update when only a new “Needs triage” item matters.

Test permissions with different users

Test as:

  • The owner.

  • A regular user who can interact with the agent.

  • A user without direct access to one source.

  • A user who should not be able to invoke the workflow.

Observe both direct access and information revealed in outputs.

Review activity and cost

Track whether the agent completed the intended outcome, required manual repair, exposed unsupported claims, or consumed unexpected credits.

When should you use the personal Agent?

Choose the personal Agent when:

  • The work is initiated by a person.

  • The relevant information is already within that person's permissions.

  • The output needs immediate interactive refinement.

  • The task changes frequently.

  • The result is primarily for the person or their current project.

  • A persistent trigger, shared ownership, and separate access model would add unnecessary administration.

A useful rule: if the person can describe the task each time and wants to review it in the same session, start with the personal Agent.

When should you build a Custom Agent?

Choose a Custom Agent when:

  • The job repeats on a schedule or event.

  • Multiple people need the same operational behavior.

  • The workflow needs explicit resource access independent of one user's session.

  • Outputs must be written to a stable destination.

  • The team needs activity history, configuration versioning, and ownership.

  • The value justifies ongoing credit usage and monitoring.

A useful rule: if the job should continue when the original builder is offline, create a governed Custom Agent.

When is neither the right choice?

Use another architecture when the workflow requires:

  • A headless service identity outside the Notion user and agent model.

  • Strict deterministic transactions across systems.

  • High-volume processing better suited to queues and code.

  • File upload through Notion's hosted MCP, which is not currently supported.

  • Broad cross-enterprise retrieval where Notion is only one of many source systems.

  • An agent workspace where documents, typed tables, files, public publishing, and external operations need one shared production layer.

In those cases, Notion can remain a source or destination while an external workflow system or agent-native workspace coordinates the process.

Notion Agents vs Notion MCP

Notion Agents and Notion MCP solve opposite connection directions.

  • Notion Agent → Notion and connected sources: the Agent lives inside Notion and acts for a user.

  • Custom Agent → configured Notion and external tools: the agent lives inside Notion with its own access and triggers.

  • External AI client → hosted Notion MCP: the AI client lives outside Notion and connects to the official remote MCP server through OAuth.

  • Notion Custom Agent → external MCP server: Notion can also use MCP tools exposed by an external service.

Do not assume that enabling hosted Notion MCP creates a background Custom Agent, or that building a Custom Agent automatically gives an external AI client access to the workspace. Authentication, permissions, and execution ownership are different.

Decision tree for choosing a personal Notion Agent, Custom Agent, or external workflow

Choose by operating identity and trigger—not by whether the prompt feels simple or complex.

A decision checklist

Before choosing, answer these questions:

  1. Who initiates the job?

  2. Whose permissions should apply?

  3. Should the workflow run without a person present?

  4. Which exact resources can the agent read and modify?

  5. Who can interact with or manage the agent?

  6. What event or schedule starts a run?

  7. What structured output proves completion?

  8. What information could cross a permission boundary?

  9. How will owners review activity and errors?

  10. What is the cost per completed outcome?

If the answers are personal, on-demand, and bounded by one user's access, use the personal Agent. If they describe a reusable team service with explicit triggers, access, ownership, and monitoring, use a Custom Agent.

Frequently asked questions

Are Notion Agents autonomous?

The personal Notion Agent is primarily on-demand. Custom Agents can run autonomously in the background after publication when a schedule, Notion event, or Slack event triggers them.

Can a Notion Agent edit databases?

The personal Agent can create and edit databases, views, forms, properties, and relations. Custom Agents can update granted databases as part of configured workflows.

Can a Custom Agent see the whole workspace?

Not by default. The owner grants specific pages, databases, and connected apps. Teams should audit the granted scope and the people allowed to interact with the agent.

Can a Custom Agent reveal information a user cannot open directly?

Yes. Notion documents that a person can interact with a shared Custom Agent whose granted resources differ from the person's direct access. The person can receive information the agent includes in its response. This is why resource access and agent-sharing permissions must be reviewed together.

Do Custom Agents cost extra?

They require Business or Enterprise and consume Notion credits. Cost depends on the workflow and run volume.

What happens if the owner leaves?

Notion supports ownership transfer. Its documentation says an agent stops running after seven days without an owner, so business-critical agents need an offboarding control.

Can a Custom Agent run from Slack?

Yes, after administrators connect Slack and the relevant permissions and channels are authorized. Triggers can respond to messages, reactions, or mentions.

Is a Custom Agent the same as an automation?

It can automate work, but it is not a deterministic rule engine. It uses models, instructions, context, and tools, so teams should evaluate variability, evidence, failure behavior, and human review.

Sources

Boundaries and failure modes

Notion Agents remain bounded by workspace permissions, owner lifecycle, product limits, and credit policy. They should not be treated as an independent authorization system or as proof that every answer is correct. Test negative permissions, trigger loops, stale sources, owner departure, and credit exhaustion before using them for consequential work.

Where Dokki fits

Dokki is useful when people and agents need to work in the same reviewable workspace with documents, tables, decisions, and explicit approval state. Compare one recurring mission in both systems and measure completed work, not the quality of an isolated chat response.

_Last verified: July 21, 2026._