Compose access from a system role, optional custom roles, and optional extra permissions. People who keep their current role are unchanged. Admin always has every permission.
This page is available to workspace admins.
System roles
Member, Editor, and Admin come with the workspace and cannot be deleted.- Member: default access for daily work
- Editor: create and share most products, without workspace settings
- Admin: every permission, including workspace settings and user management
Create a custom role
Use a custom role when several people need the same extra access. You can create up to 5 custom roles. A few AI champions should create agents and share templates without becoming admins. Create a Champion role, then assign it on Members. If usage gets too high, turn that permission off on the role. Everyone with Champion loses it at once.1
Open Create role
On Roles, under Custom roles, click Create role. The Create a custom role dialog opens.
2
Start from a role
Choose Start from Member or Editor. The dialog defaults to Editor. The new role copies those permissions. Enter a Name. The placeholder is “For example, Governor”. Add a Description if you want, then click Create role.
3
Turn permissions on
On the role page, turn permissions on by area. Duplicate permission bundles are blocked.
Give someone a role or an extra permission
On Members, click the person’s role. The Edit access drawer opens.Group permissions
Workspace roles and extras apply to a person across the workspace. Groups have their own roles. Those are not the same as Member, Editor, or Admin on Members. Open Groups.Group roles
Group roles only apply inside that group. They do not open workspace settings.- Member can use things shared with the group
- Editor can share things with the group
- Admin can do that, plus change group roles and promote people in the group
Group leader
A group leader is a group Admin with Grant extra permissions to group members. They can then grant Product permissions to people in that group, such as Create agents or Share templates. They can grant only to people in that group. Those product permissions then apply across the workspace, not only in the group. They cannot open workspace Members or Roles, cannot create custom roles, and cannot assign the workspace Editor or Admin role. They cannot turn a product on or off for the workspace. They can still change group roles. If a product is already on, they can grant it to people in their group, including expensive ones such as Workflows. Give this only to people you trust with that control. If you want several people to have the same extras, and you want to take those extras away in one place, use a custom role instead. A group leader can grant the same access again. You can also grant View governance on a group. That opens Governance only for resources owned by people in the group. Sharing the group is not enough. Rows the person already has show Already from their workspace role.Give a group leader product access
A company of a few hundred people has an AI enablement group. Anna stays workspace admin. Max is in that group. He should grant Create agents to people in the group, without billing or workspace settings.1
Make them a group Admin
On Groups, open the group. Anna and Max are both in it. Set Max to Admin in the group. He can still be Member or Editor in the workspace.
2
Turn on the group-leader permission
Turn on Grant extra permissions to group members for Max. He does not become a workspace admin.
3
Grant product permissions in the group
When Max opens the group, he opens a person in it. Extra permissions lists the product capabilities he can grant. Those extras then apply across the workspace, not only in the group.