Understanding roles and permissions

Every member has a workspace role. Connector grants are a separate permission layer: roles control workspace administration, while grants control which provider connectors a person can use through an AI client.

Roles are per workspace. The same person can be an owner in one workspace and a viewer or editor in another.

Roles at a glance

Permission Viewer Editor Owner
View connectors, groups, and activity Yes Yes Yes
Use an enabled connector Tiers from direct and group grants Tiers from direct and group grants All tiers
Enable or disable connectors No No Yes
Add, verify, or disconnect provider accounts No No Yes
Create groups and manage connector grants No No Yes
Manage workspace settings and team invitations No No Yes
Manage workspace API keys No No Yes
Delete the workspace or transfer ownership No No Yes

Viewer

Viewers can inspect the connector catalog, groups, and activity log. They can use only the read, write, or destructive connector tools included in the union of their direct grant and every active group grant.

Editor

Editors have the same gateway administration limits as viewers. Their editor role can allow write actions in other workspace features, but it does not bypass connector grants or let them manage credentials.

Owner

The owner manages the workspace, team, groups, connectors, provider accounts, grants, API keys, and workspace deletion. Active owners have implicit read, write, and destructive access to enabled connectors and do not need grants.

Every workspace has exactly one owner. Ownership is transferred to an existing member rather than assigned in an invitation.

How connector grants work

An owner can grant an enabled connector to:

  • A member, for direct access
  • A group, so every active member of that group inherits access

Every active grant includes read access. Write and destructive access are separate owner-controlled options, and overlapping direct/group grants are combined. When a connector has multiple active provider accounts, the grant must also select the account that member or group will use for its qualifying tiers. Revoking the grant or removing someone from the group takes effect on the next MCP request.

Changing a member's role

Open Team under Admin. The owner can change a member between viewer and editor, remove a member, or transfer ownership. Changing a role does not create a connector grant; manage connector access from the connector's page.

Next steps