Skip to content

Roles and permissions

Roles bundle permissions and capabilities and are assigned to users. Groups, in contrast, bundle users; both cascade to their members. You manage roles under Access in the Roles tab.

A role is a named bundle of permissions. System roles ship with CompanyGPT and cannot be deleted; custom roles are yours to manage.

"Roles" tab with system and custom roles

The overview shows the name, description and type (system or custom). Per role you can:

  • Edit permissions – the feature permissions of the role (see below)
  • Members – which users hold the role
  • Edit and Delete – custom roles only

Use Create role to add a new role.

For every role you define which features its members may use. Per feature, only the actions the platform supports are offered.

Permissions dialog of a role with features and actions

FeatureAvailable actions
AgentsUse, Create, Share, Share publicly
PromptsUse, Create, Share, Share publicly
SkillsUse, Create, Share, Share publicly
MCP serversUse, Create, Share, Share publicly, Configure OBO
Remote agentsUse, Create, Share, Share publicly
MarketplaceUse
MemoriesUse, Create, Update, Read, Opt out
File searchUse
File citationsUse
Run codeUse
Web searchUse
Multi-conversationUse
Temporary chatUse
BookmarksUse
Shared linksCreate, Share, Share publicly
People pickerView users, View groups, View roles

Feature permissions from several roles are OR-merged per user. Share publicly decides whether members may release content to the entire environment rather than to individual groups only.

Which capabilities the agent builder itself offers is controlled separately under Agent capabilities. Model access is governed under Models and providers.