AI Tools Permissions

AI Tools Permission Matrix

Role-by-role access model for workspace-owned AI Tools, including editing, publishing, running, deletion, and transfers.

Effective permission formula:Workspace Role Capability AND Entity Capability AND Plan/Feature Gate

Operation To Gate Mapping

OperationGate
Open tool editorcanRead
Run toolcanRun
Edit config/prompt/fieldscanUpdate
Publish/RevertcanUpdate
Delete toolcanDelete
Move tool across scopescanTransfer

Role Availability Matrix

RoleViewRunEdit/PublishDeleteTransfer
OwnerYesYesYesYesYes
AdminYesYesYesYesNo
ContributorYesYesYesNoNo
ReaderYesYesNoNoNo
GuestNoLimitedNoNoNo

Frequently Asked Questions

Everything you need to know

How are AI Tool permissions calculated?

Effective permission combines workspace role capability, tool entity capability, and active plan/feature gates.

Can Contributor delete tools?

No. Contributor can create/update and run tools but cannot delete or transfer.

Can Reader run tools?

Yes. Reader can view and run where supported, but cannot edit, publish, delete, or transfer.

Why is transfer blocked for Admin by default?

Transfer is role-capped in the permission model. Admin has broad management rights but transfer remains restricted unless explicitly granted.

What if a button appears but action fails?

Backend authorization is final. In edge UI states, rendered controls may appear, but protected actions still enforce capability checks server-side.

Still have questions?

Contact our support team

Need cross-entity guidance across all workspace resources?