Skip to main content

Roles

Create custom roles with fine-grained permission scopes to control exactly what each admin user can see and do.

What you can do here

  • View built-in role templates and the scopes they include
  • Create custom roles with any combination of permission scopes
  • Edit or delete custom roles
  • Assign roles to admin users from the Admin Users page

Built-in role templates

The following predefined roles are available in every organization. They are read-only and cannot be modified.

RoleIncluded permissions
OwnerAll permissions (full access)
Security AdminView and manage monitoring, security, guards, and AI discovery
IT AdminFull access to integrations, toolkits, skills, plugins, users, groups, and machine users
Read OnlyView access to all resources — no create, edit, or delete

Permission scopes

When creating a custom role, you select permissions from the following categories:

CategoryAvailable actions
Integrations (MCPs)View, Create, Edit, Delete, Publish
ToolkitsView, Create, Edit, Delete, Publish
SkillsView, Create, Edit, Delete, Publish
CommandsView, Create, Edit, Delete
RulesView, Create, Edit, Delete
HooksView, Create, Edit, Delete
PluginsView, Create, Edit, Delete
GuardsView, Create, Edit, Delete
End UsersView, Invite, Edit, Delete
Admin UsersView, Invite, Edit, Delete, Manage Roles
OrganizationView Settings, Edit Settings, Billing
GroupsView, Create, Edit, Delete
Monitoring & Shadow AIView, Manage
AuditView Logs
Manage Roles permission

The Manage Roles permission (under Admin Users) is required to create, edit, or delete custom roles and to change another admin's role assignment.

Create a custom role

  1. Click New Role.
  2. Enter a name and optional description.
  3. Select the permission scopes this role should have.
  4. Click Create Role.

New custom roles appear in the role selector when inviting or editing an admin user.

Edit or delete a role

Click on a custom role in the list to edit its name, description, or scopes. Deleting a role does not remove admin users who hold it — they fall back to no custom role assignment.