Mitigate AI Platform

Roles & Permissions

Who can do what across organizations, workspaces, and resources.

Permissions are granted at three levels — the organization, the workspace, and the individual resource.

Organization roles

  • Organization Member — belongs to the organization; can create workspaces and resources and use whatever is shared with them.
  • Organization Admin — everything a member can do, plus managing members and admins, sharing resources organization-wide, and viewing the admin dashboard and usage.
  • Organization Owner — full control of the organization: all admin abilities plus provider keys, API tokens, and the audit trail. Acts as the owner of every workspace, connector, document source, and skill — but not workflows or chats, which stay private to the user who created them.

Workspace roles

  • Workspace Owner — manages a workspace: its settings, members, and which resources are attached to it.
  • Workspace Member — can use a workspace they belong to.

Resource roles

  • Connector Owner — the user who owns the connector; can update and delete it.
  • Document Source Owner — the user who owns the document source; can update and delete it, and delete the documents inside it.
  • Skill Owner — the user who owns the skill; can update and delete it.
  • Workflow Owner — the user who owns the workflow; can run, update, and delete it.
  • Chat Owner — the user who owns the chat; can share, update, and archive it.

Connectors, document sources, and skills can each be shared in one of two ways:

  • Organization-wide (Organization shared) — anyone in the organization can add the resource to their own workspaces.
  • Workspace-limited (Workspace only) — the resource is available only in the workspaces it has been explicitly added to.

Organization level permissions

An Organization Owner acts as the owner of every workspace and shared resource — Workspace Owner, Connector Owner, Document Source Owner, and Skill Owner — so all of those owner actions are available to them. They do not gain Workflow Owner or Chat Owner access: workflows and chats stay private to the user who created them.

PermissionOrganization MemberOrganization AdminOrganization Owner
Add/remove organization admin
Add/remove organization member
Add/remove organization owner
Add/remove workspace member
Add/remove workspace owner
Configure organization provider keys and models
Create connector (org-wide)
Create connector (workspace-limited)
Create document (org-wide)
Create document (workspace-limited)
Create document source (org-wide)
Create document source (workspace-limited)
Create skill (org-wide)
Create skill (workspace-limited)
Create workspace
Manage API tokens
Run workflow
See admin dashboard
See audit trail
See chat
See connector (org-wide)
See connector (workspace-limited)
See document (org-wide)
See document (workspace-limited)
See document source (org-wide)
See document source (workspace-limited)
See skill (org-wide)
See skill (workspace-limited)
See suggestions
See token usage
See workflow
See workflow chat
See workflow run
See workspace
Update connector
Update document source
Update organization settings
Update private chat
Update private workflow
Update skill
Update workspace

Workspace level permissions

An Organization Owner acts as the owner of every workspace, so any Workspace Owner action below is also available to them.

PermissionWorkspace MemberWorkspace Owner
Add/remove connector to workspace
Add/remove document source to workspace
Add/remove skill to workspace
Add/remove workspace member
Add/remove workspace owner
Configure auto approvals for their own user
Create connector (org-wide)
Create connector (workspace-limited)
Create document (org-wide)
Create document (workspace-limited)
Create document source (org-wide)
Create document source (workspace-limited)
Create skill (org-wide)
Create skill (workspace-limited)
Delete workspace
Manage suggestions
See suggestions
See workspace
Update workspace
Update workspace provider keys

Resource level permissions

An Organization Owner acts as the Connector Owner, Document Source Owner, and Skill Owner for every such resource, so those owner actions are available to them. This does not extend to Workflow Owner or Chat Owner — workflows and chats stay private to the user who created them.

These tables use two workspace-relative roles:

  • Assigned Workspace Member — a member of a workspace the resource has been shared with.
  • Other Workspace Member — a member of the organization who has not been given access to the resource.

Connector permissions

PermissionOther Workspace MemberAssigned Workspace MemberConnector Owner
Add/remove connector to workspace
Configure connector tool
Delete connector
See connector (org-wide)
See connector (workspace-limited)
Update connector (also members)

Document permissions

PermissionOther Workspace MemberAssigned Workspace MemberDocument Source Owner
Delete document
Move document
See document (org-wide)
See document (workspace-limited)

Document Source permissions

PermissionOther Workspace MemberAssigned Workspace MemberDocument Source Owner
Add/remove document source to workspace
Delete document source
Process document source
See document source (org-wide)
See document source (workspace-limited)
Update document source
Upload files to a document source

Skill permissions

Organization-wide skills are visible to everyone; workspace-limited skills are only visible through an assigned workspace.

PermissionOther Workspace MemberAssigned Workspace MemberSkill Owner
Add/remove skill to workspace
Delete skill
See skill (org-wide)
See skill (workspace-limited)
Update skill

Workflow permissions

An Organization Owner can view any workflow, but only the Workflow Owner can run, edit, or delete it — no organization role can modify another user's workflow.

PermissionWorkflow Owner
Delete workflow
Run workflow
See workflow
Update workflow

Chat permissions

An Organization Owner cannot see other users' private chats — only shared chats and the embedded widget chat are visible to them. This includes chats produced by a workflow: the owner can see the workflow but not the chats it created.

PermissionChat Owner
Archive chat
See chat
See workflow chat
Share chat
Unarchive chat
Update chat

On this page