Understanding roles and permissions
Every member has a workspace role. Connector grants are a separate permission layer: roles control workspace administration, while grants control which provider connectors a person can use through an AI client.
Roles are per workspace. The same person can be an owner in one workspace and a viewer or editor in another.
Roles at a glance
| Permission | Viewer | Editor | Owner |
|---|---|---|---|
| View connectors, groups, and activity | Yes | Yes | Yes |
| Use an enabled connector | Tiers from direct and group grants | Tiers from direct and group grants | All tiers |
| Enable or disable connectors | No | No | Yes |
| Add, verify, or disconnect provider accounts | No | No | Yes |
| Create groups and manage connector grants | No | No | Yes |
| Manage workspace settings and team invitations | No | No | Yes |
| Manage workspace API keys | No | No | Yes |
| Delete the workspace or transfer ownership | No | No | Yes |
Viewer
Viewers can inspect the connector catalog, groups, and activity log. They can use only the read, write, or destructive connector tools included in the union of their direct grant and every active group grant.
Editor
Editors have the same gateway administration limits as viewers. Their editor role can allow write actions in other workspace features, but it does not bypass connector grants or let them manage credentials.
Owner
The owner manages the workspace, team, groups, connectors, provider accounts, grants, API keys, and workspace deletion. Active owners have implicit read, write, and destructive access to enabled connectors and do not need grants.
Every workspace has exactly one owner. Ownership is transferred to an existing member rather than assigned in an invitation.
How connector grants work
An owner can grant an enabled connector to:
- A member, for direct access
- A group, so every active member of that group inherits access
Every active grant includes read access. Write and destructive access are separate owner-controlled options, and overlapping direct/group grants are combined. When a connector has multiple active provider accounts, the grant must also select the account that member or group will use for its qualifying tiers. Revoking the grant or removing someone from the group takes effect on the next MCP request.
Changing a member's role
Open Team under Admin. The owner can change a member between viewer and editor, remove a member, or transfer ownership. Changing a role does not create a connector grant; manage connector access from the connector's page.