Skip to main content
A member’s permissions come from their roles. Most permissions act on resources (apps, knowledge bases, or agents), and a member can exercise them only on the resources they can access. On any single resource, you can also override what a member’s roles allow. Permissions of this kind are resource permissions. The other permissions, like managing members or installing plugins, act on the workspace itself and aren’t tied to any resource.
See Permission Reference for which permissions are resource permissions and what each permission allows.

Example

Maya holds the Editor role, so she has the permission to edit apps. (Role: decides who can do what) Your Q4 Revenue app holds sensitive data, so you keep Maya off its allowed members list. The app never appears for her, even though she’s an Editor. (Resource access: controls who can access a resource) If you add Maya into the list, the app shows up for her and she can edit it like any other app. To limit her to viewing it, override her role permissions there. (Exception: overrides role permissions for a specific resource)

Decide Who Can Do What

Assign each member a role. Roles are managed in Settings > Roles & Permissions and assigned to members in Settings > Members. When a member holds multiple roles, their permissions combine.

System Roles

Every workspace includes a set of system roles. To see everything a role grants, open it and click View. Each system role carries its own workspace permissions, plus the default resource permission sets shown below. See what resource permissions each default set includes in Settings > Permission Set.

Custom Roles

When the system roles don’t fit how your team works, create a custom role and choose exactly which permissions it includes. A new workspace also starts with any custom roles predefined in the Enterprise Dashboard. Deleting a custom role removes it from every member assigned to it.

Control Who Can Access a Resource

Managing resource access needs View and manage access permissions, held by default by the Owner, Admins, and the resource’s creator.
Control who can access a resource in its Resource Access tab:
  • To open it to every workspace member, including those who join later, turn Automatically include workspace members on.
  • To limit it to specific members, turn the toggle off, then manage its allowed members list yourself.
The creator is tagged Maintainer in the allowed members list and can’t be removed from it. The workspace Owner and Admins always have access to every resource in the workspace.
Apps and agents start open to all workspace members, while knowledge bases start open only to their creator, the workspace Owner, and Admins.To keep a new app or agent private, turn Automatically include workspace members off right after creating it.
Members without access don’t see the resource at all, and access alone doesn’t show it either: a Restricted Member, whose role grants no permission, sees nothing unless you make an exception for them.

Make Exceptions

By default, a member’s permissions on a resource come from their role. To make an exception, in the resource’s Resource Access tab, switch the member’s Access permission from By role permissions to a permission set. You can pick a built-in set, or create your own in Settings > Permission Set. The set replaces the role’s permissions on that resource alone.
Exceptions don’t apply to the workspace Owner, Admins, or the resource’s creator. They always have Full Control on the resource.