The App, Knowledge Base, and Agent resource permissions below are also constrained by resource access. A member can use them only on the apps, knowledge bases, and agents their resource access reaches, even when their role grants the permission.See Roles and Permissions for details.
Workspace
| Permission | What it lets a member do |
|---|---|
| Manage members | Invite members and change their roles (both also need Manage roles and permission sets), and remove members. |
| Manage roles and permission sets | Create, edit, duplicate, and delete custom roles and permission sets. |
| Manage customization | Customize workspace branding, such as replacing the WebApp logo and removing Dify branding. |
Skills
| Permission | What it lets a member do |
|---|---|
| View Skill | View the workspace skill library and skill content, and export the latest saved content. |
| Edit Skill | Create library skills, edit drafts, import skill packages, and duplicate skills. |
| Publish Skill | Publish skill drafts and restore earlier versions to the current draft. |
| Delete Skill | Delete skills from the workspace. |
Members without View Skill don’t see Skills in the main navigation, even if they hold the other skill permissions. These permissions apply workspace-wide, not to individual skills.
Applications
| Permission | What it lets a member do |
|---|---|
| Create apps | Create apps from scratch, a template, or a DSL file, and duplicate existing apps. |
| Manage app tags | Create, edit, and assign tags to apps. |
| View and use App Library | See the App Library in the main navigation, where published apps are listed to open. |
| Create and modify snippets | Create snippets, edit and publish them, and export them. |
| Manage snippets | Delete snippets. |
App Resource Permissions
| Permission | What it lets a member do |
|---|---|
| Preview app | See the app in the list, without opening its detail pages. |
| View access points | Open the app’s Access Point page and see its web app, backend API access, MCP service, and trigger settings. |
| Manage access points | Change the app’s access point settings:
|
| View app orchestration | Open the app’s orchestration and configuration pages in read-only mode, and view its conversations, comments, variables, and annotations. |
| Test and use app | Run and debug the app, including chat, completion, agent, and workflow test runs. |
| Edit app information and orchestrate app | Edit the app’s configuration and workflow, and manage its annotations, comments, and variables. |
| Import and export app DSL | Import and export the app’s DSL, and publish it to the creators platform. |
| Publish and manage app versions | Publish the app, and open its version history to name, restore, or delete earlier versions. |
| View app monitoring | View the app’s monitoring page and usage statistics. |
| View and configure app monitoring traces | View and change the app’s external tracing configuration. |
| View and manage logs and annotations | View the app’s logs and annotations. |
| View and manage access permissions | Open the app’s Resource Access page and manage who can access it. |
| Deploy app | See Deploy in the navigation of a Workflow or Chatflow app, and deploy the app. |
| Delete app | Delete the app. |
Knowledge Bases
| Permission | What it lets a member do |
|---|---|
| Create knowledge bases | Create knowledge bases, sync from sources like Notion, and import knowledge pipelines. |
| Manage knowledge base tags | Create, edit, and assign tags to knowledge bases. |
| Connect external knowledge bases | Connect an external knowledge base provider. |
| Manage knowledge base API keys | Create and delete the knowledge base Service API keys. |
Knowledge Base Resource Permissions
| Permission | What it lets a member do |
|---|---|
| Preview knowledge base | See the knowledge base in the list, without opening its detail pages. |
| View knowledge base content and settings | Open the knowledge base in read-only mode and view its documents, segments, and settings. |
| Edit knowledge base content and settings | Edit the knowledge base’s settings, documents, segments, and metadata. |
| Upload knowledge base documents | Add or upload documents to the knowledge base. |
| Delete knowledge base documents | Delete documents from the knowledge base. |
| Download knowledge base documents | Download documents from the knowledge base. |
| View and run retrieval tests | Run retrieval testing on the knowledge base. |
| Test pipeline | Test-run the knowledge pipeline. |
| Import and export pipeline DSL | Import and export the knowledge pipeline DSL. |
| Publish and manage pipeline versions | Release the knowledge pipeline and manage its versions. |
| View and manage knowledge base access permissions | Open the knowledge base’s Resource Access page and manage who can access it. |
| Delete knowledge base | Delete the knowledge base. |
Agents
| Permission | What it lets a member do |
|---|---|
| Create agents | Create agents from scratch, duplicate agents you can view, and save new agents from a workflow’s Agent node. |
Agent Resource Permissions
| Permission | What it lets a member do |
|---|---|
| View agent basic information | See the agent in the list, without opening its detail pages. |
| Edit agent information and configuration | Edit the agent’s basic information and its configuration in Configure. Building by chatting also needs Test and run agent. |
| Test and run agent | Open Configure and test-run the agent. Changing its configuration also needs Edit agent information and configuration. |
| Publish and manage agent versions | Publish the agent and manage its versions. |
| View access points | Open the agent’s Access Point page and see its web app and API access settings, and which workflows use it. |
| Manage access points | Change the agent’s web app and API access settings. |
| View and manage logs | View the agent’s Logs page and manage its run logs there. |
| View agent monitoring | View the agent’s Monitoring page. |
| View and manage access permissions | Open the agent’s Resource Access page and manage who can access it. |
| Import and export agent DSL | Export the agent’s DSL and import agent DSL files from the Agents page. |
| Delete agent | Delete the agent. |
Integrations
Plugins
| Permission | What it lets a member do |
|---|---|
| Install and update plugins | Install and update plugins from the Marketplace, GitHub, or a local package. |
| Delete plugins | Uninstall plugins. |
| Debug plugins | Get a debugging key and remotely debug plugins. |
| Configure models | Add and configure model providers, models, and plugin endpoints. |
| Configure auto updates | Set plugin auto-update preferences. |
Tools and MCP
| Permission | What it lets a member do |
|---|---|
| Manage tools | Create, edit, delete, and authorize custom, API, and workflow tools. |
| Manage MCP | Create, edit, delete, and authorize MCP providers. |
Credentials
| Permission | What it lets a member do |
|---|---|
| View and use credentials | Use configured credentials and switch the active credential or preferred provider. |
| Add credentials | Add a new credential, such as a model provider’s API key or a data source authorization. |
| Edit and delete credentials | Update and delete credentials, and manage OAuth and custom clients. |
API Extensions
| Permission | What it lets a member do |
|---|---|
| Manage API extension configuration | Add, edit, and delete API-based extensions. |