Skip to main content
Admin › Users › Groups & Permissions
Groups bundle users for unified permission management.
  • Design groups by department, role, project, etc., to match your organization.

Why Groups?

Creating a Group

1

Select the Groups & Permissions tab

Pick the Groups & Permissions tab under Admin Panel > Users. The list shows each group name along with the number of linked organizations and member users.
2

Create a new group

Click the + icon (tooltip: “Create group”). The creation modal only takes the group name (e.g., “Marketing Team”) and description.
Add User Group modal open on the group list screen

Click '+' on the group list → Add User Group modal

3

Edit group — detailed settings

Open the created group to configure details in the edit modal’s General / Permissions / Organization / Users tabs.
4

Connect to Organizational Unit (optional)

In the edit modal’s Organization tab, link this group to a specific organizational unit. All users in the linked OU automatically get the group’s permissions — useful for applying the same permission set to an entire department.
Linking the “Marketing Team” group to “Company / Marketing Division” OU automatically grants permission to new employees as IdP sync adds them to Marketing Division.

Group Permission Settings

Configure per-group permissions in the Permissions tab of the edit modal.
  • The specification method varies by permission type.
  • Admin & Workspace permissions — specify via a level dropdown
  • Sharing, Chat & Feature permissions — specify via ON/OFF toggles
Edit User Group permissions tab — Skill, Tool, Scheduled task, Marketplace, and Tag access alongside the sharing toggles

Group permission settings — workspace permissions (level dropdowns) and sharing permissions (ON/OFF toggles)

Permission Levels

These are the levels applied to Admin and Workspace permissions.
  • The available levels vary by item.
Set each item to None, Read, or Write (no Access level). Read allows viewing; Write allows create/edit/delete.Default is the value filled in when you create a new group. Only Scheduled task access and Tag access permission start out open; everything else is None.
Tool access and Tag access permission carry explanatory tooltips on screen.
  • Tool access — a warning that granting Write lets users upload arbitrary code to the server
  • Tag access permission — Read views and assigns existing tags; Write also creates, edits, and deletes them
You can delegate parts of admin features to regular users.
  • The number of usable levels varies by permission item.
  • User management, Evaluation, and Settings — None, Access, Read, Write (4 levels)
  • Monitoring — None, Access, Read (3 levels; no Write, as it’s a read-only area)
All are ON/OFF toggles.Sharing permissions (6)
  • Public agent sharing, public knowledge sharing, public prompt sharing, public tool sharing, public database sharing, public glossary sharing
Chat permissions (10)
  • File upload, chat controls, chat deletion, allow chat editing
  • Speech-to-text (STT), text-to-speech (TTS), calls
  • Multi-model, temporary chat, force temporary chat Force temporary chat appears on screen only while Allow temporary chat is on. Turning temporary chat off hides this item as well.
Feature permissions (7)
  • Direct tool server, web search, image generation
  • Gmail, Calendar, Google Drive, code interpreter

Default Permissions

Set default permissions applied to users not in any group.
  • Configure them under Default Permissions at the bottom of the group list; they apply to all users with the User role.
Default permissions are the initial permissions for users not in any group. Per least-privilege principle, set defaults restrictively and grant additional permissions through groups as needed.

Group ↔ Organizational Unit Mapping

In the Organization tab of the edit modal (Edit User Group), you can map this group to one or more organizational units (OUs).
  • All members of mapped OUs automatically inherit the group’s permissions, so when IdP sync adds a new employee to an OU, permissions apply without any manual action.
OUs themselves are imported via IdP sync (Entra/Google Workspace OIDC) or created manually under Admin > Organizations. See Organization Management for OU creation and sync.
Mapping the “Marketing” group to the “Company / Marketing” OU means that the moment IdP adds a new hire to the Marketing OU, they receive the group’s permission set automatically — eliminating the operational overhead of adding/removing users from groups one by one.

User Management

User list, roles, add/edit, usage limits

Organizations

Organization/OU hierarchy, Entra ID sync, organization-based access control

Inquiries

Receive and handle user inquiries