> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloosphere.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Sharing & Permissions

> How to share the resources you create with groups and organizational units

When you create a resource, only you can see it. Add groups or organizational units to open it up to others.

<Frame caption="Access Control modal — add a group and set its permission, opened via the Access button">
  <img src="https://mintcdn.com/cloocus/KaBbk3O9rWexEgxk/images/en/collaboration/sharing-access-modal.png?fit=max&auto=format&n=KaBbk3O9rWexEgxk&q=85&s=bf89faf9d0e8b47d3c5fd7a1210b4fd7" alt="Access Control modal" width="1913" height="905" data-path="images/en/collaboration/sharing-access-modal.png" />
</Frame>

***

## Before you share — permissions have two axes

Permissions in Cloosphere split into two separate axes. A user must pass **both** to reach a resource.

| Axis                  | What it decides                                                          | Who sets it    |
| --------------------- | ------------------------------------------------------------------------ | -------------- |
| **Group permissions** | Whether a person can use the feature at all (for example, create agents) | Admin          |
| **Access control**    | Who can reach one specific resource                                      | Resource owner |

This page covers **access control**. Creating groups and granting feature permissions is an admin task — see [Groups & Permissions](/en/admin/groups).

<Note>
  If a resource screen shows no permission area and no **Access** button, your admin has not granted your group Write permission for that feature.
</Note>

### Read-level group permission — what gets blocked

If the group permission your admin granted is **Read**, you can view and use the resource but cannot edit it. A greyed-out save button, or a missing **Access** button, is almost always this.

| Element                                      | Read     | Write  |
| -------------------------------------------- | -------- | ------ |
| **Save & Update** / **Save & Create** button | Disabled | Normal |
| Add / delete item buttons                    | Disabled | Normal |
| **Access** button                            | Hidden   | Shown  |

If you need to edit, ask your admin to raise your group's permission for that feature to **Write**.

<Note>
  The **\[...]** menu in the workspace list is shown to the **owner only**, regardless of permission.
</Note>

<Tip>
  Read-only access still lets you view and use the resource. You can chat with a read-only agent, but you cannot change its prompt or model.
</Tip>

***

## Sharing a resource

### Opening access control

Set permissions on the resource's create or edit screen. It appears in one of two forms, depending on the screen.

| If the screen shows this                         | Open it this way                                                    |
| ------------------------------------------------ | ------------------------------------------------------------------- |
| An **Access** button with a lock icon at the top | Click it to open the **Access Control** modal                       |
| A **Permission** area on the screen itself       | Use it as is — **Groups** and **Organizational Units** follow below |

How you pick Read or Write also depends on the form — click the **Read** badge to toggle it, or choose from a dropdown.

<Frame caption="Inline permission area on a create screen — toggle Read/Write from the dropdown">
  <img src="https://mintcdn.com/cloocus/KaBbk3O9rWexEgxk/images/en/collaboration/sharing-access-inline.png?fit=max&auto=format&n=KaBbk3O9rWexEgxk&q=85&s=b9bb42557074a1b36d60f0f3a614f003" alt="Inline permission area" width="1910" height="907" data-path="images/en/collaboration/sharing-access-inline.png" />
</Frame>

<Note>
  The same feature can use different forms on its create and edit screens. Check whether the screen has an **Access** button at the top first.
</Note>

### Adding groups and organizational units

<Steps>
  <Step title="Confirm the permission is Private">
    Check that the **Permission** dropdown reads **Private**. You can only add groups and organizational units while it is Private.
  </Step>

  <Step title="Add a group">
    Pick a group from the **Groups** selector. Added groups get **Read** by default.
  </Step>

  <Step title="Switch to Write">
    Click the **Read** badge, or choose **Write** from the dropdown. To revert, switch it back to **Read**.
  </Step>

  <Step title="Add an organizational unit">
    Pick an organization from the **Organizational Units** selector. Choosing a parent organization also grants access to members of its child organizations.
  </Step>

  <Step title="Save">
    Click **Save & Update** or **Update**. Permissions apply immediately.
  </Step>
</Steps>

<Tip>
  **Prefer groups over organizational units when granting Write.** Use organizational units to open Read access broadly, and put people who need to edit into a group that carries Write.
</Tip>

### Read and Write

**Write includes Read.** You do not need to add Read separately for the same target.

Here is what Read and Write mean for each feature. The order follows the workspace tabs.

| Feature              | Read                                                   | Write                                 |
| -------------------- | ------------------------------------------------------ | ------------------------------------- |
| **Agents**           | Select and use in chat                                 | Edit agent settings                   |
| **Flows**            | Run the flow                                           | Edit the flow                         |
| **Knowledge**        | View, open documents                                   | Add/delete documents, change settings |
| **Databases**        | Use DB queries                                         | Change DB connection settings         |
| **Glossaries**       | Reference terms                                        | Add/edit terms                        |
| **Knowledge Graphs** | View and search the graph                              | Edit the graph                        |
| **Guardrails**       | View the guardrail                                     | Edit guardrail rules                  |
| **Prompts**          | Use the prompt                                         | Edit the prompt                       |
| **Skills**           | Attach to an agent and use                             | Edit the skill instructions           |
| **Tools**            | Use the tool                                           | Change tool settings                  |
| **Marketplace**      | Attach to an agent and use                             | Change service settings               |
| **Tags**             | No access control — governed by group permissions only | —                                     |

***

## Making a resource public

Switch the **Permission** dropdown to **Public** and every user can read the resource. Write still belongs to the owner and admins only.

<Note>
  If the dropdown offers no **Public** option, your admin has not granted public sharing permission for that feature. Some features are restricted so that only admins can make them public. See [Groups & Permissions](/en/admin/groups).
</Note>

***

## Per-resource notes

<AccordionGroup>
  <Accordion title="Channels">
    Set channel permissions by opening the channel in the sidebar and choosing **Edit Channel**.

    * Groups and organizational units can only be granted **Read**. The badge is fixed at Read and does not toggle to Write.
    * Read permission alone lets a user both read and post messages. In a channel, Read means participation.
    * Creating and deleting channels is restricted to admins.

    <Frame caption="Channel permissions — groups and organizational units are fixed at Read">
      <img src="https://mintcdn.com/cloocus/KaBbk3O9rWexEgxk/images/en/collaboration/sharing-channel-permission.png?fit=max&auto=format&n=KaBbk3O9rWexEgxk&q=85&s=0819ddb4cdeb3509260d6a75f4c4c0b3" alt="Channel permission" width="1913" height="906" data-path="images/en/collaboration/sharing-channel-permission.png" />
    </Frame>
  </Accordion>

  <Accordion title="Projects">
    Projects do not support group or organizational unit sharing. Neither the create screen nor the settings screen has a permission area.

    To hand a project to someone else, use **Copy to Users** on the settings screen. This creates an independent copy for them, so later edits to your original do not reach that copy.
  </Accordion>

  <Accordion title="Scheduled tasks">
    Scheduled tasks support both approaches. You can share one through access control, or hand over a copy.

    For a scheduled task to appear at all, however, your admin must both enable the feature and grant the group permission. Both conditions must hold.
  </Accordion>
</AccordionGroup>

***

## How a permission is decided

Access requests are evaluated in this order.

```mermaid theme={null}
flowchart TD
    A[Resource access request] --> B{Admin?}
    B -->|Yes| C[Full access granted]
    B -->|No| D{Owner?}
    D -->|Yes| C
    D -->|No| E{Public?}
    E -->|Yes| F[Read allowed]
    E -->|No| G{Group match?}
    G -->|Yes| H[Apply that permission]
    G -->|No| I{Org unit match?}
    I -->|Yes| H
    I -->|No| J[Access denied]
```

If a user belongs to several groups, the **highest permission wins**. Read from group A and Write from group B resolves to Write.

***

## Example setup

| Agent                | Read                          | Write              |
| -------------------- | ----------------------------- | ------------------ |
| **Shared assistant** | Public                        | AI team group      |
| **HR assistant**     | HR team group                 | HR managers group  |
| **Sales analytics**  | Executives group, Sales group | Data team group    |
| **Dev helper**       | Engineering division org unit | Backend team group |

Granting Read broadly through organizational units and Write narrowly through groups keeps things manageable.

***

## Reference

<Accordion title="Advanced: how permissions are stored">
  The permissions you set on screen are stored in the resource's `access_control` field in this shape. You never need to edit it directly — it is here for API integration and troubleshooting.

  ```json theme={null}
  {
    "access_control": {
      "read":  { "group_ids": [], "user_ids": [], "org_unit_ids": [] },
      "write": { "group_ids": [], "user_ids": [], "org_unit_ids": [] }
    }
  }
  ```

  | State   | Value        |
  | ------- | ------------ |
  | Public  | `null`       |
  | Private | Empty object |
</Accordion>

<Columns cols={2}>
  <Card title="Groups & Permissions" icon="users" href="/en/admin/groups">
    How admins create groups and grant feature and public-sharing permissions
  </Card>

  <Card title="Organization Management" icon="building" href="/en/admin/organizations">
    Org unit hierarchy, Entra ID sync, and OU-based access control
  </Card>
</Columns>

***

## FAQ

<AccordionGroup>
  <Accordion title="If a resource is public, can anyone edit it?">
    No. Public opens Read only. Editing and deleting stay with the owner and admins.
  </Accordion>

  <Accordion title="How do I share with one specific user?">
    There is no way to name an individual user directly. Create a group containing only that user, then grant the group permission.
  </Accordion>

  <Accordion title="What happens when a user belongs to several groups?">
    The highest permission applies. Read from one group and Write from another resolves to Write.
  </Accordion>

  <Accordion title="Does a parent org unit's permission reach its children?">
    If you grant access to Engineering division, members of its child organizations — Backend team, Frontend team — can reach the resource too. Matching walks upward from the user's own organization.
  </Accordion>

  <Accordion title="Do permission changes take effect immediately?">
    Yes. They apply the moment you save, with no deploy or restart needed.
  </Accordion>
</AccordionGroup>
