Role Management (in Settings > Users Management > Role Management) implements role-based access control (RBAC) for accounts, tools, and agentic apps. Every user must have a role. When you invite a user, assign a role that matches their responsibilities. You can reassign roles at any time. Key points:
- Account creator → automatically assigned Master Admin (highest account-level access).
- Tool creator → automatically assigned Tool Admin.
- App creator → automatically assigned App Owner.
- New users get the Member role by default.
Key Concepts
Roles
A role groups users by job function to streamline permission management. Agent Platform supports two role categories:Role Types
Role type defines the scope of a role—what modules and actions it governs.Access Levels
System Roles
System roles have preset permissions and cannot be modified or deleted. To customize a system role’s permissions, duplicate it as a custom role.Account Roles
Tool Roles
App Roles
Custom Roles
Custom roles apply to Account and Tool role types only. Use them to grant only the permissions a specific user needs. Example: A “Banking Tool Conversation Moderator” role with full access to guardrail configuration but no access to create or deploy tools. Rules:- Custom roles appear in the invitation dropdown and can be assigned to invited users.
- You cannot delete a custom role that is assigned to active users or included in a pending invitation. Reassign or remove those users first.
Module-wise Permissions
The tables below show default permissions for each role. Yes = access granted; No = no access.Admin Role Permissions
Tool Role Permissions
App Role Permissions
Access level summary:Evaluation Role Permissions
Role Management Dashboard
The Role Management dashboard lists all system and custom roles with their type, description, creator, and last-updated date. To access:- Go to Settings > Users Management > Role Management.
- Summary counts: Total Roles, System Roles, Custom Roles.
- Role table: Role name, Role Type, Description, Created by, Last Updated On.
The Last Updated On column is blank for system roles because they cannot be modified.
Search for a Role
- Go to the Role Management dashboard.
- Click the Search field.
- Type the role name. Matching results appear instantly.
Manage System Roles
View a System Role
- On the Role Management dashboard, click the … (ellipsis) menu for a system role.
- Select View.
Duplicate a System Role
Duplicating copies the role’s name, type, and all permission settings into a new custom role that you can modify.Changes to the duplicate do not affect the original system role.
- On the Role Management dashboard, click the … menu for a system role.
- Select Duplicate.
_copy. Rename it as needed.
Manage Custom Roles
Add a Custom Role
- Go to Settings > Users Management > Role Management.
- Click Add New Role.
- Enter a unique Role Name and Role Description.
- Select a Role Type: Account or Tool.
- Set the Models access level before enabling its sub-permissions. Skipping this disables them automatically.
- Setting Settings to Full → sets Integrations and User Management to Full and enables all sub-permissions.
- Setting Settings to No Access → sets Integrations to View, User Management to No Access.
- Setting Settings to Custom → sets Integrations and User Management to Custom, where you select individual permissions.
- Click Create.
Edit a Custom Role
- The Role Type cannot be changed after creation. Create a new custom role if you need a different type.
- Updating a custom role immediately changes permissions for all users currently assigned to it.
- On the Role Management dashboard, click the … menu for the custom role.
- Select Edit.
- Update Role Name, Role Description, or Access level.
- Click Update.
Delete a Custom Role
You can only delete custom roles not assigned to any active users. Bulk deletion is not supported. Prerequisite: Ensure no users are assigned to the role. If they are, do one of the following first:- Reassign a different role: Go to Settings > Users Management > Users, click the user’s Account Role field, and select a new role.
- Delete the assigned users: Go to Users Management and delete the users individually or in bulk.
- On the Role Management dashboard, click the … menu for the custom role.
- Select Delete.
- Click Confirm.