Roles & Permissions
Who can do what across organizations, workspaces, and resources.
Permissions are granted at three levels — the organization, the workspace, and the individual resource.
Organization roles
- Organization Member — belongs to the organization; can create workspaces and resources and use whatever is shared with them.
- Organization Admin — everything a member can do, plus managing members and admins, sharing resources organization-wide, and viewing the admin dashboard and usage.
- Organization Owner — full control of the organization: all admin abilities plus provider keys, API tokens, and the audit trail. Acts as the owner of every workspace, connector, document source, and skill — but not workflows or chats, which stay private to the user who created them.
Workspace roles
- Workspace Owner — manages a workspace: its settings, members, and which resources are attached to it.
- Workspace Member — can use a workspace they belong to.
Resource roles
- Connector Owner — the user who owns the connector; can update and delete it.
- Document Source Owner — the user who owns the document source; can update and delete it, and delete the documents inside it.
- Skill Owner — the user who owns the skill; can update and delete it.
- Workflow Owner — the user who owns the workflow; can run, update, and delete it.
- Chat Owner — the user who owns the chat; can share, update, and archive it.
Connectors, document sources, and skills can each be shared in one of two ways:
- Organization-wide (Organization shared) — anyone in the organization can add the resource to their own workspaces.
- Workspace-limited (Workspace only) — the resource is available only in the workspaces it has been explicitly added to.
Organization level permissions
An Organization Owner acts as the owner of every workspace and shared resource — Workspace Owner, Connector Owner, Document Source Owner, and Skill Owner — so all of those owner actions are available to them. They do not gain Workflow Owner or Chat Owner access: workflows and chats stay private to the user who created them.
| Permission | Organization Member | Organization Admin | Organization Owner |
|---|---|---|---|
| Add/remove organization admin | |||
| Add/remove organization member | |||
| Add/remove organization owner | |||
| Add/remove workspace member | |||
| Add/remove workspace owner | |||
| Configure organization provider keys and models | |||
| Create connector (org-wide) | |||
| Create connector (workspace-limited) | |||
| Create document (org-wide) | |||
| Create document (workspace-limited) | |||
| Create document source (org-wide) | |||
| Create document source (workspace-limited) | |||
| Create skill (org-wide) | |||
| Create skill (workspace-limited) | |||
| Create workspace | |||
| Manage API tokens | |||
| Run workflow | |||
| See admin dashboard | |||
| See audit trail | |||
| See chat | |||
| See connector (org-wide) | |||
| See connector (workspace-limited) | |||
| See document (org-wide) | |||
| See document (workspace-limited) | |||
| See document source (org-wide) | |||
| See document source (workspace-limited) | |||
| See skill (org-wide) | |||
| See skill (workspace-limited) | |||
| See suggestions | |||
| See token usage | |||
| See workflow | |||
| See workflow chat | |||
| See workflow run | |||
| See workspace | |||
| Update connector | |||
| Update document source | |||
| Update organization settings | |||
| Update private chat | |||
| Update private workflow | |||
| Update skill | |||
| Update workspace |
Workspace level permissions
An Organization Owner acts as the owner of every workspace, so any Workspace Owner action below is also available to them.
| Permission | Workspace Member | Workspace Owner |
|---|---|---|
| Add/remove connector to workspace | ||
| Add/remove document source to workspace | ||
| Add/remove skill to workspace | ||
| Add/remove workspace member | ||
| Add/remove workspace owner | ||
| Configure auto approvals for their own user | ||
| Create connector (org-wide) | ||
| Create connector (workspace-limited) | ||
| Create document (org-wide) | ||
| Create document (workspace-limited) | ||
| Create document source (org-wide) | ||
| Create document source (workspace-limited) | ||
| Create skill (org-wide) | ||
| Create skill (workspace-limited) | ||
| Delete workspace | ||
| Manage suggestions | ||
| See suggestions | ||
| See workspace | ||
| Update workspace | ||
| Update workspace provider keys |
Resource level permissions
An Organization Owner acts as the Connector Owner, Document Source Owner, and Skill Owner for every such resource, so those owner actions are available to them. This does not extend to Workflow Owner or Chat Owner — workflows and chats stay private to the user who created them.
These tables use two workspace-relative roles:
- Assigned Workspace Member — a member of a workspace the resource has been shared with.
- Other Workspace Member — a member of the organization who has not been given access to the resource.
Connector permissions
| Permission | Other Workspace Member | Assigned Workspace Member | Connector Owner |
|---|---|---|---|
| Add/remove connector to workspace | |||
| Configure connector tool | |||
| Delete connector | |||
| See connector (org-wide) | |||
| See connector (workspace-limited) | |||
| Update connector (also members) |
Document permissions
| Permission | Other Workspace Member | Assigned Workspace Member | Document Source Owner |
|---|---|---|---|
| Delete document | |||
| Move document | |||
| See document (org-wide) | |||
| See document (workspace-limited) |
Document Source permissions
| Permission | Other Workspace Member | Assigned Workspace Member | Document Source Owner |
|---|---|---|---|
| Add/remove document source to workspace | |||
| Delete document source | |||
| Process document source | |||
| See document source (org-wide) | |||
| See document source (workspace-limited) | |||
| Update document source | |||
| Upload files to a document source |
Skill permissions
Organization-wide skills are visible to everyone; workspace-limited skills are only visible through an assigned workspace.
| Permission | Other Workspace Member | Assigned Workspace Member | Skill Owner |
|---|---|---|---|
| Add/remove skill to workspace | |||
| Delete skill | |||
| See skill (org-wide) | |||
| See skill (workspace-limited) | |||
| Update skill |
Workflow permissions
An Organization Owner can view any workflow, but only the Workflow Owner can run, edit, or delete it — no organization role can modify another user's workflow.
| Permission | Workflow Owner |
|---|---|
| Delete workflow | |
| Run workflow | |
| See workflow | |
| Update workflow |
Chat permissions
An Organization Owner cannot see other users' private chats — only shared chats and the embedded widget chat are visible to them. This includes chats produced by a workflow: the owner can see the workflow but not the chats it created.
| Permission | Chat Owner |
|---|---|
| Archive chat | |
| See chat | |
| See workflow chat | |
| Share chat | |
| Unarchive chat | |
| Update chat |