Available Permissions
Permissions are organized by feature area. Custom roles and extra permissions use the same list. Admins can customize these in Roles settings. To create and assign roles, see Roles and extra permissions. Open Roles in the app.Agents
Workflows
Files
Users can still share folders and knowledge bases directly with individual users and groups even when this permission is disabled. Restricting it only blocks workspace-wide grants.
Groups
Skills
File Templates
Integrations
Sharing a custom API integration with the whole workspace is an admin action in Integrations settings.
Projects
Prompt Library
Governance
When Governance is on, every workspace admin has this access. Grant it to others as an extra permission or custom role on Members or Roles. See Roles and extra permissions and Governance.
Recommended Setup
For most organizations, we recommend:- Keep defaults for Members - Allow creating agents, uploading documents, and syncing folders so everyone can build use cases
- Use Editors as moderators - Editors help keep the workspace organized by managing shared content and public groups
- Restrict workspace-wide sharing initially - Start with Editor/Admin only for workspace-wide sharing, then expand as needed
- Custom roles when several people need the same extra access. Create them on Roles
- Group permissions when a group leader should grant product access inside a group. Set this on Groups