Personas Permissions

Role-based access control for workspace-owned personas.

Policy Resolution

Persona permissions follow workspace role capability with plan and feature-gate enforcement.

Effective Permission = Workspace Role Capability AND Plan/Feature Gate

Operation To Gate Mapping

OperationGate
Add persona versioncanContribute
Edit version or defaultcanUpdate
API integration actionscanUpdate
Delete persona or versioncanDelete
Move private persona to workspacecanUpdate

Role Availability Matrix

RoleViewAdd VersionEdit/Default/APIDeleteMove Private Persona
OwnerYesYesYesYesYes
AdminYesYesYesYesYes
ContributorYesYesYesNoYes
ReaderYesNoNoNoNo
GuestNoNoNoNoNo
Note:
Backend authorization is always final for persona updates, deletions, and defaults.

FAQ

How are persona permissions evaluated?+

Persona permissions are primarily workspace-capability driven in current implementation, then constrained by plan and feature gates.

Q1

Can Contributor edit persona versions?+

Yes. Contributor can add and edit versions, but cannot delete persona versions or personas.

Q2

Can Reader edit personas?+

No. Reader can view but cannot add, edit, default, or delete persona versions.

Q3

Can Guest access workspace personas?+

No. Guest does not have workspace-owned persona management access.

Q4

Why are some controls visible but action is blocked?+

In edge UI states, controls may render; backend authorization still enforces role and capability limits.

Q5

Tip:
For cross-entity policy details, see Workspace Permissions Matrix.