- User → agent — which people can view, chat with, update, delete, or manage an agent’s secrets.
- Agent → agent — which agents may call which other agents.
User and org management
Create users, assign roles, build teams and departments.
User → agent access
Ownership, the public flag, and explicit grants.
Agent → agent MCP access
Per-agent connector and tool permissions.
Platform reference
Full technical reference.
Roles
Every user has exactly one role. Each tier includes everything below it.
A role sets what kind of action a user may attempt. Whether they can act on a specific agent is decided by user → agent access.
Role is not superuser. Superuser is a separate flag. It bypasses organization-visibility scoping and unlocks platform-wide routes: creating users, creating departments and teams, OIDC group mappings, directory sync. Setting
role to admin does not grant it — see user and org management.