Skip to content

Permissions

A role is a set of the permissions below. Permissions apply within one workspace. To assign them, see Users and roles.

The server checks permissions on every request. The menu hides pages you can’t use, but hiding is not the protection.

“Yes” means the default role has the permission in every workspace.

Permission Allows admin user viewer
settings.view Opening Settings and seeing System Health. Reading or changing values needs settings.manage. Yes
settings.manage Reading and changing workspace settings and provider keys, configuring single sign-on, managing integration keys under Integrations, and Messaging Yes
Permission Allows admin user viewer
agents.view Seeing agents, skills and MCP servers Yes Yes Yes
agents.create Creating agents and skills Yes Yes
agents.edit Editing agents and skills, their channels, reminders and A2A clients Yes Yes
agents.delete Deleting agents and skills Yes
agents.publish Publishing a draft to every channel, rolling back to an earlier version, and deciding publish requests Yes
Permission Allows admin user viewer
tools.view Seeing custom and predefined tools Yes Yes Yes
tools.create Creating custom tools Yes Yes
tools.edit Editing custom tools and configuring predefined tools Yes Yes
tools.delete Deleting custom tools Yes
Permission Allows admin user viewer
knowledge_base.view Seeing knowledge bases and their documents Yes Yes Yes
knowledge_base.create Creating knowledge bases Yes Yes
knowledge_base.edit Uploading documents and changing a knowledge base Yes Yes
knowledge_base.delete Deleting knowledge bases Yes
Permission Allows admin user viewer
users.view Opening Users and listing roles Yes
users.manage Creating, editing and deleting roles under Roles Yes

Inviting, changing roles, deactivating, removing and resetting passwords require the admin role itself, not only these permissions.

Permission Allows admin user viewer
conversations.view Listing conversations, conversation statistics, and Feedback Yes Yes Yes
conversations.audit Opening any transcript, the sensitive data report and the Access log Yes
conversations.pii_reveal Revealing masked sensitive values Yes
conversations.manage Exporting, Re-scan, and applying the retention window on demand. Exporting one conversation also needs conversations.audit. Yes

See Sensitive data.

Permission Allows admin user viewer
dashboard.view Dashboard statistics and Analytics Yes Yes Yes
posthog.view Analytics dashboards Yes Yes Yes
analytics.view Analytics. No default role has it; add it to a custom role if needed.
Permission Allows admin user viewer
budgets.view Opening Budgets and current usage Yes Yes
budgets.manage Creating, editing and deleting budget limits Yes

See Budgets.

Permission Allows admin user viewer
evaluations.view Seeing evaluation datasets and results Yes Yes Yes
evaluations.manage Creating and editing datasets and cases Yes Yes
evaluations.run Starting evaluation runs. Runs call the model, so they spend tokens. Yes Yes
Permission Allows admin user viewer
logs.view Nothing in a workspace role. Logs, the service’s application log viewer, is available only to platform administrators. Yes
system.admin Using the Agent Builder Yes
chat.use Held by the webapp_viewer role. No screen checks it today: any active member can use the workspace web chat.

webapp_viewer holds only chat.use. People with it can sign in to the workspace web chat and talk to its agents, and see nothing in the admin console.

Platform administrators operate the VirtuAI service. They are the only people who can create workspaces and see Logs, and in any workspace they belong to they pass every permission check. This isn’t a permission: it can’t be added to a role, granted by a workspace admin, or mapped from SSO groups.