Asana AI Teammates use shared memory with access-control claims
Asana says its AI Teammates retain workflow context across teams, but buyers still need to test how permissions isolate confidential work.
By Colin Brandt · Enterprise Reporter
· 3 min read
Asana AI Teammates shared memory is the work-management company’s answer to a common enterprise-agent problem: a tool that completes a single chat request but does not carry team knowledge into the next workflow. Asana’s chief product officer, Arnab Bose, said its Agentic Work Management system is already used by several live customers, including FedEx, though Asana did not disclose deployment scale, contract value, pricing or independently verified outcomes.
The pitch rests on Asana’s Work Graph, its data structure connecting tasks to projects, projects to portfolios, and portfolios to company goals. Bose said that structure lets an AI Teammate work from shared organizational context rather than from one employee’s prompt or local files. Asana says task outcomes, feedback and related metadata can persist for later work, creating a form of team-wide memory.
How does Asana AI Teammates shared memory protect confidential work?
Asana says the retention question is inseparable from permissions. Bose used the example of an agent trained during a confidential M&A project: an employee without access to that project should not be able to retrieve or use memory formed there. He said Asana built access controls that distinguish between events that create memory and tasks that only execute work.
That is a product-design claim, not an independently tested security result. The available material does not describe the technical mechanism for memory isolation, retention periods, testing methods, data sent to external models, or any third-party security assessment. It also does not establish whether the controls prevent disclosures under every use case.
Asana’s September 2025 product announcement said agents work inside its existing platform, where users and administrators can view activity and outcomes, provide feedback, and set data-access permissions, operating parameters and consumption limits. The product was in beta at that point, with general availability then expected in the first quarter of fiscal 2027. Bose’s later comments indicate some customer deployments, but do not establish broad current availability.
What does the system do beyond chat?
Bose said Asana routes more demanding work to heavier frontier models, naming Anthropic’s Opus and OpenAI models as examples, while assigning simpler tasks to faster, less expensive models. The company aims to hide model selection and prompt construction from employees. It also says it charges a fixed amount per completed task rather than making customers manage model choice, tokens or run limits directly. No price was disclosed.
CoreWeave is an early example cited by Bose, not an independently verified case study in the supplied reporting. He said its product-launch process begins with a document that triggers creation of a project structure and tasks; specialized agents then monitor bottlenecks and forecast infrastructure costs against historical budgets.
For buyers, shared memory changes the diligence checklist. The issue is not only whether an agent can retain useful context. It is which context becomes durable, who can retrieve it, what permissions it inherits, when a human must approve action, and whether administrators can trace what the agent accessed and did. Asana has described controls for those questions, but the evidence does not independently validate their performance.
This story draws on original reporting from VentureBeat.