See Permission Reference for which permissions are resource permissions and what each permission allows.
Example
Maya holds the Editor role, so she has the permission to edit apps. (Role: decides who can do what) Your Q4 Revenue app holds sensitive data, so you keep Maya off its allowed members list. The app never appears for her, even though she’s an Editor. (Resource access: controls who can access a resource) If you add Maya into the list, the app shows up for her and she can edit it like any other app. To limit her to viewing it, override her role permissions there. (Exception: overrides role permissions for a specific resource)Decide Who Can Do What
Assign each member a role. Roles are managed in Settings > Roles & Permissions and assigned to members in Settings > Members. When a member holds multiple roles, their permissions combine.System Roles
Every workspace includes a set of system roles. To see everything a role grants, open it and click View. Each system role carries its own workspace permissions, plus the default resource permission sets shown below.
See what resource permissions each default set includes in Settings > Permission Set.
Custom Roles
When the system roles don’t fit how your team works, create a custom role and choose exactly which permissions it includes. A new workspace also starts with any custom roles predefined in the Enterprise Dashboard. Deleting a custom role removes it from every member assigned to it.Control Who Can Access a Resource
Managing resource access needs View and manage access permissions, held by default by the Owner, Admins, and the resource’s creator.
- To open it to every workspace member, including those who join later, turn Automatically include workspace members on.
- To limit it to specific members, turn the toggle off, then manage its allowed members list yourself.
Apps and agents start open to all workspace members, while knowledge bases start open only to their creator, the workspace Owner, and Admins.To keep a new app or agent private, turn Automatically include workspace members off right after creating it.
Make Exceptions
By default, a member’s permissions on a resource come from their role. To make an exception, in the resource’s Resource Access tab, switch the member’s Access permission from By role permissions to a permission set. You can pick a built-in set, or create your own in Settings > Permission Set. The set replaces the role’s permissions on that resource alone.Exceptions don’t apply to the workspace Owner, Admins, or the resource’s creator. They always have Full Control on the resource.