> ## Documentation Index
> Fetch the complete documentation index at: https://enterprise-docs.dify.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Permission Reference

> What each permission lets a member do

This page lists every permission and the actions it allows, so you can see exactly what you grant when you build a custom role or permission set.

<Note>
  The App, Knowledge Base, and Agent resource permissions below are also constrained by resource access. A member can use them only on the apps, knowledge bases, and agents their resource access reaches, even when their role grants the permission.

  See [Roles and Permissions](/en/3.13.x/use/workspace/roles-and-permissions#control-who-can-access-a-resource) for details.
</Note>

## Workspace

| Permission | What it lets a member do |
| :- | :- |
| **Manage members** | Invite members and change their roles (both also need **Manage roles and permission sets**), and remove members. |
| **Manage roles and permission sets** | Create, edit, duplicate, and delete custom roles and permission sets. |
| **Manage customization** | Customize workspace branding, such as replacing the WebApp logo and removing Dify branding. |

## Skills

| Permission | What it lets a member do |
| :- | :- |
| **View Skill** | View the workspace skill library and skill content, and export the latest saved content. |
| **Edit Skill** | Create library skills, edit drafts, import skill packages, and duplicate skills. |
| **Publish Skill** | Publish skill drafts and restore earlier versions to the current draft. |
| **Delete Skill** | Delete skills from the workspace. |

<Note>
  Members without **View Skill** don't see **Skills** in the main navigation, even if they hold the other skill permissions. These permissions apply workspace-wide, not to individual skills.
</Note>

## Applications

| Permission | What it lets a member do |
| :- | :- |
| **Create apps** | Create apps from scratch, a template, or a DSL file, and duplicate existing apps. |
| **Manage app tags** | Create, edit, and assign tags to apps. |
| **View and use App Library** | See the App Library in the main navigation, where published apps are listed to open. |
| **Create and modify snippets** | Create snippets, edit and publish them, and export them. |
| **Manage snippets** | Delete snippets. |

## App Resource Permissions

| Permission | What it lets a member do |
| :- | :- |
| **Preview app** | See the app in the list, without opening its detail pages. |
| **View access points** | Open the app's **Access Point** page and see its web app, backend API access, MCP service, and trigger settings. |
| **Manage access points** | Change the app's access point settings: <ul><li>Web app: turn it on or off, regenerate its URL, embed it in a site, customize its frontend and branding, and set who can access it.</li><li>Backend API: turn it on or off and manage API keys.</li><li>MCP service: turn it on or off, edit its description, and regenerate its URL.</li><li>Triggers: turn each trigger on or off.</li></ul> |
| **View app orchestration** | Open the app's orchestration and configuration pages in read-only mode, and view its conversations, comments, variables, and annotations. |
| **Test and use app** | Run and debug the app, including chat, completion, agent, and workflow test runs. |
| **Edit app information and orchestrate app** | Edit the app's configuration and workflow, and manage its annotations, comments, and variables. |
| **Import and export app DSL** | Import and export the app's DSL, and publish it to the creators platform. |
| **Publish and manage app versions** | Publish the app, and open its version history to name, restore, or delete earlier versions. |
| **View app monitoring** | View the app's monitoring page and usage statistics. |
| **View and configure app monitoring traces** | View and change the app's external tracing configuration. |
| **View and manage logs and annotations** | View the app's logs and annotations. |
| **View and manage access permissions** | Open the app's **Resource Access** page and manage who can access it. |
| **Deploy app** | See **Deploy** in the navigation of a Workflow or Chatflow app, and deploy the app. |
| **Delete app** | Delete the app. |

## Knowledge Bases

| Permission | What it lets a member do |
| :- | :- |
| **Create knowledge bases** | Create knowledge bases, sync from sources like Notion, and import knowledge pipelines. |
| **Manage knowledge base tags** | Create, edit, and assign tags to knowledge bases. |
| **Connect external knowledge bases** | Connect an external knowledge base provider. |
| **Manage knowledge base API keys** | Create and delete the knowledge base Service API keys. |

## Knowledge Base Resource Permissions

| Permission | What it lets a member do |
| :- | :- |
| **Preview knowledge base** | See the knowledge base in the list, without opening its detail pages. |
| **View knowledge base content and settings** | Open the knowledge base in read-only mode and view its documents, segments, and settings. |
| **Edit knowledge base content and settings** | Edit the knowledge base's settings, documents, segments, and metadata. |
| **Upload knowledge base documents** | Add or upload documents to the knowledge base. |
| **Delete knowledge base documents** | Delete documents from the knowledge base. |
| **Download knowledge base documents** | Download documents from the knowledge base. |
| **View and run retrieval tests** | Run retrieval testing on the knowledge base. |
| **Test pipeline** | Test-run the knowledge pipeline. |
| **Import and export pipeline DSL** | Import and export the knowledge pipeline DSL. |
| **Publish and manage pipeline versions** | Release the knowledge pipeline and manage its versions. |
| **View and manage knowledge base access permissions** | Open the knowledge base's **Resource Access** page and manage who can access it. |
| **Delete knowledge base** | Delete the knowledge base. |

## Agents

| Permission | What it lets a member do |
| :- | :- |
| **Create agents** | Create agents from scratch, duplicate agents you can view, and save new agents from a workflow's Agent node. |

## Agent Resource Permissions

| Permission | What it lets a member do |
| :- | :- |
| **View agent basic information** | See the agent in the list, without opening its detail pages. |
| **Edit agent information and configuration** | Edit the agent's basic information and its configuration in **Configure**. Building by chatting also needs **Test and run agent**. |
| **Test and run agent** | Open **Configure** and test-run the agent. Changing its configuration also needs **Edit agent information and configuration**. |
| **Publish and manage agent versions** | Publish the agent and manage its versions. |
| **View access points** | Open the agent's **Access Point** page and see its web app and API access settings, and which workflows use it. |
| **Manage access points** | Change the agent's web app and API access settings. |
| **View and manage logs** | View the agent's **Logs** page and manage its run logs there. |
| **View agent monitoring** | View the agent's **Monitoring** page. |
| **View and manage access permissions** | Open the agent's **Resource Access** page and manage who can access it. |
| **Import and export agent DSL** | Export the agent's DSL and import agent DSL files from the **Agents** page. |
| **Delete agent** | Delete the agent. |

## Integrations

### Plugins

| Permission | What it lets a member do |
| :- | :- |
| **Install and update plugins** | Install and update plugins from the Marketplace, GitHub, or a local package. |
| **Delete plugins** | Uninstall plugins. |
| **Debug plugins** | Get a debugging key and remotely debug plugins. |
| **Configure models** | Add and configure model providers, models, and plugin endpoints. |
| **Configure auto updates** | Set plugin auto-update preferences. |

### Tools and MCP

| Permission | What it lets a member do |
| :- | :- |
| **Manage tools** | Create, edit, delete, and authorize custom, API, and workflow tools. |
| **Manage MCP** | Create, edit, delete, and authorize MCP providers. |

### Credentials

| Permission | What it lets a member do |
| :- | :- |
| **View and use credentials** | Use configured credentials and switch the active credential or preferred provider. |
| **Add credentials** | Add a new credential, such as a model provider's API key or a data source authorization. |
| **Edit and delete credentials** | Update and delete credentials, and manage OAuth and custom clients. |

### API Extensions

| Permission | What it lets a member do |
| :- | :- |
| **Manage API extension configuration** | Add, edit, and delete API-based extensions. |
