A role is a set of the permissions below. Permissions apply within one workspace. To assign them, see Users and roles.
The server checks permissions on every request. The menu hides pages you can’t use, but hiding is not the protection.
“Yes” means the default role has the permission in every workspace.
| Permission |
Allows |
admin |
user |
viewer |
settings.view |
Opening Settings and seeing System Health. Reading or changing values needs settings.manage. |
Yes |
|
|
settings.manage |
Reading and changing workspace settings and provider keys, configuring single sign-on, managing integration keys under Integrations, and Messaging |
Yes |
|
|
| Permission |
Allows |
admin |
user |
viewer |
agents.view |
Seeing agents, skills and MCP servers |
Yes |
Yes |
Yes |
agents.create |
Creating agents and skills |
Yes |
Yes |
|
agents.edit |
Editing agents and skills, their channels, reminders and A2A clients |
Yes |
Yes |
|
agents.delete |
Deleting agents and skills |
Yes |
|
|
agents.publish |
Publishing a draft to every channel, rolling back to an earlier version, and deciding publish requests |
Yes |
|
|
| Permission |
Allows |
admin |
user |
viewer |
tools.view |
Seeing custom and predefined tools |
Yes |
Yes |
Yes |
tools.create |
Creating custom tools |
Yes |
Yes |
|
tools.edit |
Editing custom tools and configuring predefined tools |
Yes |
Yes |
|
tools.delete |
Deleting custom tools |
Yes |
|
|
| Permission |
Allows |
admin |
user |
viewer |
knowledge_base.view |
Seeing knowledge bases and their documents |
Yes |
Yes |
Yes |
knowledge_base.create |
Creating knowledge bases |
Yes |
Yes |
|
knowledge_base.edit |
Uploading documents and changing a knowledge base |
Yes |
Yes |
|
knowledge_base.delete |
Deleting knowledge bases |
Yes |
|
|
| Permission |
Allows |
admin |
user |
viewer |
users.view |
Opening Users and listing roles |
Yes |
|
|
users.manage |
Creating, editing and deleting roles under Roles |
Yes |
|
|
Inviting, changing roles, deactivating, removing and resetting passwords require the admin role itself, not only these permissions.
| Permission |
Allows |
admin |
user |
viewer |
conversations.view |
Listing conversations, conversation statistics, and Feedback |
Yes |
Yes |
Yes |
conversations.audit |
Opening any transcript, the sensitive data report and the Access log |
Yes |
|
|
conversations.pii_reveal |
Revealing masked sensitive values |
Yes |
|
|
conversations.manage |
Exporting, Re-scan, and applying the retention window on demand. Exporting one conversation also needs conversations.audit. |
Yes |
|
|
See Sensitive data.
| Permission |
Allows |
admin |
user |
viewer |
dashboard.view |
Dashboard statistics and Analytics |
Yes |
Yes |
Yes |
posthog.view |
Analytics dashboards |
Yes |
Yes |
Yes |
analytics.view |
Analytics. No default role has it; add it to a custom role if needed. |
|
|
|
| Permission |
Allows |
admin |
user |
viewer |
budgets.view |
Opening Budgets and current usage |
Yes |
Yes |
|
budgets.manage |
Creating, editing and deleting budget limits |
Yes |
|
|
See Budgets.
| Permission |
Allows |
admin |
user |
viewer |
evaluations.view |
Seeing evaluation datasets and results |
Yes |
Yes |
Yes |
evaluations.manage |
Creating and editing datasets and cases |
Yes |
Yes |
|
evaluations.run |
Starting evaluation runs. Runs call the model, so they spend tokens. |
Yes |
Yes |
|
| Permission |
Allows |
admin |
user |
viewer |
logs.view |
Nothing in a workspace role. Logs, the service’s application log viewer, is available only to platform administrators. |
Yes |
|
|
system.admin |
Using the Agent Builder |
Yes |
|
|
chat.use |
Held by the webapp_viewer role. No screen checks it today: any active member can use the workspace web chat. |
|
|
|
webapp_viewer holds only chat.use. People with it can sign in to the workspace web chat and talk to its agents, and see nothing in the admin console.
Platform administrators operate the VirtuAI service. They are the only people who can create workspaces and see Logs, and in any workspace they belong to they pass every permission check. This isn’t a permission: it can’t be added to a role, granted by a workspace admin, or mapped from SSO groups.