Skip to content

Roles and Teams

A role is a named set of permissions. A team is a group of people who share roles. You give a person access with a role or with a team.

A member with no role and no team has no access. The member sees No Workspace access.

Two Built-In Roles Cover Admin Work

AgentZ creates two roles for you. You cannot edit them.

Role Scope What it grants
Superadmin Organization Every current and future capability, in the organization and in every workspace
Workspace Admin One workspace Every capability in that workspace. Only a Superadmin can change who holds it

Every other role is a custom role. AgentZ ships no default Member or Viewer role.

An organization can have more than one Superadmin. Add a second one by choosing Superadmin under Direct roles in an invitation. AgentZ blocks the removal or demotion of the last active Superadmin.

Create a Custom Role

  1. In the organization sidebar, select Roles, then Create role. The role editor opens.
  2. Enter a Role name. The limit is 80 characters.
  3. Choose a Permission scope: the organization or one named workspace.
  4. Select Add permissions and pick the permissions the role needs.
  5. Select Create. The toast says Role created.

An organization role holds a separate set of permissions for each scope. A grant for the organization does not apply in a workspace. Grant it for that workspace too.

To make a role for one workspace only, open Workspace settings → Roles inside that workspace and select Create role.

Access Levels Build on Each Other

Each resource row has an access level. Each level includes the levels below it.

Level What it lets the holder do
Read-only See the resource
Read and create See and create
Read, create, and modify See, create and change
Full access See, create, change and delete

Rows exist for Skills, Sandboxes, MCP connections and Inference providers at both scopes. MCP connections has no modify level. Inference pools and Lens exist only in a workspace. Lens has read access only.

Agent Capabilities Control Who Builds and Shares Agents

Agent capabilities exist only at workspace scope. AgentZ adds the capabilities a choice depends on.

Capability What it lets the holder do Also needs
Author Create and edit agents Sandboxes read, Skills read
Share Authored Share agents the holder created None
Share Non-Authored Share agents other members created Use Shared
Use Shared Run agents others shared None
Read Shared Secret Read secret metadata on shared agents Use Shared
Write Shared Secret Create and update secrets on shared agents Read Shared Secret
Delete Shared Secret Delete secrets on shared agents Write Shared Secret

The creator of an agent owns it. The owner can use, change and delete it. The owner shares it with the Share Authored capability. Another member needs a capability here plus a share. See Share an agent.

Create a Team

  1. In the organization sidebar, select Teams, then Create team. The team editor opens.
  2. Enter a Name, for example Security operations.
  3. In Members, choose at least one active member.
  4. In Roles, choose the roles the team holds.
  5. Select Create team. The toast says Team created.

Every member of the team inherits the team roles. You can also add a team to an invitation.

Next Step

Continue with Share an agent.