Browse Platform
Platform · Account

Users, Groups & Access

Manage account users and use groups to grant project, Flow, and shared Connection access.

4 min readLast reviewed July 27, 2026

#Users and groups

Users are the people invited to the account. Each user has an account type and can belong to one or more groups. Use the Administrator user role for account-wide administration. Use the User role plus groups when access should be limited.

Account Admin is a user role. Project Admin, Resources, Member, and Flow Runner are access patterns implemented through group scope and policy. They are listed together below because they are the common choices an administrator makes when granting access, but they are not five interchangeable role values.

Groups connect account users to granular policies that grant shared connections and skill collections.
Screenshot previewGroups connect account users to granular policies that grant shared connections and skill collections.
Acme Groups administration page listing Sales Organization with granular policy access

#Choose an access type

Choose the narrowest group scope that matches the work: project administration, selected Flow access, or a granular resource policy.
Screenshot previewChoose the narrowest group scope that matches the work: project administration, selected Flow access, or a granular resource policy.
Create Group dialog in light mode showing Project Access, Chat Access, and Granular Policy Access scope choices
Access typeConfigure it asWhat it allows
Account AdminUser type: AdministratorAccess to all projects plus account Users, Groups, and Integrations. Account Owners add billing and cancellation authority.
Project AdminGroup scope: Project AccessAdministrator access to the selected projects, including their Flows, Data, Connections, and settings.
ResourcesGroup scope: Granular Policy Access; policy type: ResourcesControls which shared Connections and Skill Collections members can discover and use. A Connection’s tool settings still decide whether each tool is denied, asks, or runs.
MemberThe standard Member groupAllows a regular user to create a personal Workspace using the Integrations permitted by the Member policy. Add other groups when the user also needs shared Connections or project access.
Flow RunnerGroup scope: Chat AccessAllows members to run only the selected compatible Flows without project administration access.

#User permissions and management

Membership confirms which users inherit the shared resources selected by the group policy.
Screenshot previewMembership confirms which users inherit the shared resources selected by the group policy.
Sales Organization Membership dialog showing the Acme test user as a current member
  1. 01

    Open Account → Users

    Review current users or choose Invite User.

  2. 02

    Choose the user type

    Select Administrator for account-wide administration. Select User when access will come from groups.

  3. 03

    Select groups

    Add every group the person needs. A new regular user normally starts in Member and can belong to additional project, Flow, or Resources groups.

  4. 04

    Review membership later

    Open the user or the group whenever responsibilities change, and remove access that is no longer required.

#Manage groups

The Resources policy grants selected shared connections and skill collections to members of the group.
Screenshot previewThe Resources policy grants selected shared connections and skill collections to members of the group.
Sales Organization group editor showing Shared Connections and Skill Collections resource access
  1. 01

    Open Account → Groups

    Review existing groups or choose Create Group.

  2. 02

    Choose the scope

    Use Project Access for project administrators, Chat Access for Flow Runners, or Granular Policy Access for resource and personal Workspace policies.

  3. 03

    Configure the boundary

    Select the projects, Flows, or Resources included in the group. A Resources policy determines which shared Connections and Skill Collections members can access.

  4. 04

    Manage membership

    Save the group, open Membership, and add the intended users.

  5. 05

    Test as a member

    Verify the user can see only the intended project, Flow, or Connection before treating the policy as complete.

#Agent permissions and inheritance

An Integration holds the application credentials. A Connection is the security boundary agents use to discover and call tools. Sharing a Connection with the account makes it eligible for account use; it does not grant every user access.

For a regular user, the Resources group policy determines which shared Connections are visible. The Connection then determines which tools are enabled and whether a tool is set to Deny, Ask, or Allow. Personal and Workspace settings can narrow the effective access further.

Access shows the permissions inherited by new chats and any workspace-level changes.
Screenshot previewAccess shows the permissions inherited by new chats and any workspace-level changes.
Workspace Access settings showing inherited skills and shared connection permissions