> ## Documentation Index
> Fetch the complete documentation index at: https://enterprise-docs.dify.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and Permissions

> Control what each member can do by combining roles with resource access

A member's permissions come from their **roles**.

Most permissions act on resources (apps, knowledge bases, or agents), and a member can exercise them only on the resources they can **access**. On any single resource, you can also override what a member's roles allow. Permissions of this kind are *resource permissions*.

The other permissions, like managing members or installing plugins, act on the workspace itself and aren't tied to any resource.

<Info>
  See [Permission Reference](/en/3.13.x/use/workspace/permission-reference) for which permissions are resource permissions and what each permission allows.
</Info>

## Example

Maya holds the Editor role, so she has the permission to edit apps. ([**Role: decides who can do what**](#decide-who-can-do-what))

Your Q4 Revenue app holds sensitive data, so you keep Maya off its allowed members list. The app never appears for her, even though she's an Editor. ([**Resource access: controls who can access a resource**](#control-who-can-access-a-resource))

If you add Maya into the list, the app shows up for her and she can edit it like any other app. To limit her to viewing it, override her role permissions there. ([**Exception: overrides role permissions for a specific resource**](#make-exceptions))

## Decide Who Can Do What

Assign each member a role. Roles are managed in **Settings** > **Roles & Permissions** and assigned to members in **Settings** > [**Members**](/en/3.13.x/use/workspace/team-members-management).

When a member holds multiple roles, their permissions combine.

### System Roles

Every workspace includes a set of system roles. To see everything a role grants, open it and click **View**.

Each system role carries its own workspace permissions, plus the default resource permission sets shown below.

| Role | Apps | Knowledge bases | Agents |
| :- | :- | :- | :- |
| Owner, Admin | Full Control | Full Control | Full Control |
| Editor | Edit Content | Edit Content | Edit Content |
| Normal | View Monitoring and Access Points | None | View Agent Basic Info, View Access Points |
| Restricted Member | None | None | None |

See what resource permissions each default set includes in **Settings** > **Permission Set**.

### Custom Roles

When the system roles don't fit how your team works, create a custom role and choose exactly which permissions it includes. A new workspace also starts with any custom roles predefined in the Enterprise Dashboard.

Deleting a custom role removes it from every member assigned to it.

## Control Who Can Access a Resource

<Info>
  Managing resource access needs **View and manage access permissions**, held by default by the Owner, Admins, and the resource's creator.
</Info>

Control who can access a resource in its **Resource Access** tab:

* To open it to every workspace member, including those who join later, turn **Automatically include workspace members** on.

* To limit it to specific members, turn the toggle off, then manage its allowed members list yourself.

The creator is tagged **Maintainer** in the allowed members list and can't be removed from it.

The workspace Owner and Admins always have access to every resource in the workspace.

<Info>
  Apps and agents start open to all workspace members, while knowledge bases start open only to their creator, the workspace Owner, and Admins.

  To keep a new app or agent private, turn **Automatically include workspace members** off right after creating it.
</Info>

Members without access don't see the resource at all, and access alone doesn't show it either: a Restricted Member, whose role grants no permission, sees nothing unless you make an exception for them.

## Make Exceptions

By default, a member's permissions on a resource come from their role.

To make an exception, in the resource's **Resource Access** tab, switch the member's **Access permission** from **By role permissions** to a permission set.

You can pick a built-in set, or create your own in **Settings** > **Permission Set**. The set replaces the role's permissions on that resource alone.

<Info>
  Exceptions don't apply to the workspace Owner, Admins, or the resource's creator. They always have **Full Control** on the resource.
</Info>
