Disable Enable button for private AI Catalog items outside managing project
What does this MR do and why?
Fixes the first of the two UX bugs described in #596801 (closed): private AI Catalog items show an active Enable button even when the user is viewing them from outside their managing project.
A private catalog item can only ever be enabled in the project it was created in. Today the Enable button is clickable from anywhere, and submitting it silently enables the item in the item's owning project rather than the context the user is in — a confusing cross-project side effect with no UI signal.
After this MR, the Enable button is disabled in those cases with a tooltip naming the managing project, matching the scope copy already shown in the consumer modal body ("This item is private and can only be enabled in the project it was created in…").
The second part of #596801 (closed) (filtering already-enabled projects from the Enable modal dropdown) ships separately in !233159 (merged).
How it works
- New
isOutsideOwningProjectcomputed onAiCatalogItemActions:- Returns
falsefor public items (no scope restriction). - For private items, compares the current
projectIdinject againstitem.project.id(converted withgetIdFromGraphQLId). - Any namespace that isn't the owning project — another project, a group, or the Explore page — is treated as outside.
- Returns
canEnableandenableButtonDisabledare extended with the new guard.canEnableflows into the consumer modal's primary action, so the modal's submit is also disabled in this state.enableButtonTooltipexplains the constraint with the managing project'snameWithNamespace: "This private agent can only be enabled in its managing project: Group 1 / Project 1."
No backend, GraphQL, or policy changes. No feature flag — the rule is a UI hardening on top of an already-correct model; the existing backend authorization remains the source of truth.
Steps to reproduce
- In your GDK, create a private agent in project
group-a/project-1(AI Catalog → New agent, set visibility to Private). - Navigate to the same catalog from a different project (e.g.
group-b/project-2) where you are at least a Maintainer, or from the global Explore catalog. - Open the private agent's detail page.
- Before this MR: the Enable button is active. Clicking it opens the modal; submitting enables the agent in
group-a/project-1(the owning project), not where you are. - After this MR: the Enable button is disabled and greyed out. Hovering shows: "This private agent can only be enabled in its managing project: Group A / Project 1."
Screenshots or screen recordings
Private Agent on Explore Level
| before | after |
|---|---|
![]() |
![]() |
Private Agent on managing Group Level (no changes)
| before | after |
|---|---|
![]() |
![]() |
| Walkthrough before |
|---|
| Walkthrough after |
|---|
Related to #596801 (closed).



