Users, Groups & Access
Manage account users and use groups to grant project, Flow, and shared Connection access.
#Users and groups
Users are the people invited to the account. Each user has an account type and can belong to one or more groups. Use the Administrator user role for account-wide administration. Use the User role plus groups when access should be limited.
Account Admin is a user role. Project Admin, Resources, Member, and Flow Runner are access patterns implemented through group scope and policy. They are listed together below because they are the common choices an administrator makes when granting access, but they are not five interchangeable role values.
#Choose an access type
| Access type | Configure it as | What it allows |
|---|---|---|
| Account Admin | User type: Administrator | Access to all projects plus account Users, Groups, and Integrations. Account Owners add billing and cancellation authority. |
| Project Admin | Group scope: Project Access | Administrator access to the selected projects, including their Flows, Data, Connections, and settings. |
| Resources | Group scope: Granular Policy Access; policy type: Resources | Controls which shared Connections and Skill Collections members can discover and use. A Connection’s tool settings still decide whether each tool is denied, asks, or runs. |
| Member | The standard Member group | Allows a regular user to create a personal Workspace using the Integrations permitted by the Member policy. Add other groups when the user also needs shared Connections or project access. |
| Flow Runner | Group scope: Chat Access | Allows members to run only the selected compatible Flows without project administration access. |
#User permissions and management
- 01
Open Account → Users
Review current users or choose Invite User.
- 02
Choose the user type
Select Administrator for account-wide administration. Select User when access will come from groups.
- 03
Select groups
Add every group the person needs. A new regular user normally starts in Member and can belong to additional project, Flow, or Resources groups.
- 04
Review membership later
Open the user or the group whenever responsibilities change, and remove access that is no longer required.
#Manage groups
- 01
Open Account → Groups
Review existing groups or choose Create Group.
- 02
Choose the scope
Use Project Access for project administrators, Chat Access for Flow Runners, or Granular Policy Access for resource and personal Workspace policies.
- 03
Configure the boundary
Select the projects, Flows, or Resources included in the group. A Resources policy determines which shared Connections and Skill Collections members can access.
- 04
Manage membership
Save the group, open Membership, and add the intended users.
- 05
Test as a member
Verify the user can see only the intended project, Flow, or Connection before treating the policy as complete.
#Agent permissions and inheritance
An Integration holds the application credentials. A Connection is the security boundary agents use to discover and call tools. Sharing a Connection with the account makes it eligible for account use; it does not grant every user access.
For a regular user, the Resources group policy determines which shared Connections are visible. The Connection then determines which tools are enabled and whether a tool is set to Deny, Ask, or Allow. Personal and Workspace settings can narrow the effective access further.