Roles and Teams¶
A role is a named set of permissions. A team is a group of people who share roles. You give a person access with a role or with a team.
A member with no role and no team has no access. The member sees No Workspace access.
Two Built-In Roles Cover Admin Work¶
AgentZ creates two roles for you. You cannot edit them.
| Role | Scope | What it grants |
|---|---|---|
| Superadmin | Organization | Every current and future capability, in the organization and in every workspace |
| Workspace Admin | One workspace | Every capability in that workspace. Only a Superadmin can change who holds it |
Every other role is a custom role. AgentZ ships no default Member or Viewer role.
An organization can have more than one Superadmin. Add a second one by choosing Superadmin under Direct roles in an invitation. AgentZ blocks the removal or demotion of the last active Superadmin.
Create a Custom Role¶
- In the organization sidebar, select Roles, then Create role. The role editor opens.
- Enter a Role name. The limit is 80 characters.
- Choose a Permission scope: the organization or one named workspace.
- Select Add permissions and pick the permissions the role needs.
- Select Create. The toast says Role created.
An organization role holds a separate set of permissions for each scope. A grant for the organization does not apply in a workspace. Grant it for that workspace too.
To make a role for one workspace only, open Workspace settings → Roles inside that workspace and select Create role.
Access Levels Build on Each Other¶
Each resource row has an access level. Each level includes the levels below it.
| Level | What it lets the holder do |
|---|---|
| Read-only | See the resource |
| Read and create | See and create |
| Read, create, and modify | See, create and change |
| Full access | See, create, change and delete |
Rows exist for Skills, Sandboxes, MCP connections and Inference providers at both scopes. MCP connections has no modify level. Inference pools and Lens exist only in a workspace. Lens has read access only.
Agent Capabilities Control Who Builds and Shares Agents¶
Agent capabilities exist only at workspace scope. AgentZ adds the capabilities a choice depends on.
| Capability | What it lets the holder do | Also needs |
|---|---|---|
| Author | Create and edit agents | Sandboxes read, Skills read |
| Share Authored | Share agents the holder created | None |
| Share Non-Authored | Share agents other members created | Use Shared |
| Use Shared | Run agents others shared | None |
| Read Shared Secret | Read secret metadata on shared agents | Use Shared |
| Write Shared Secret | Create and update secrets on shared agents | Read Shared Secret |
| Delete Shared Secret | Delete secrets on shared agents | Write Shared Secret |
The creator of an agent owns it. The owner can use, change and delete it. The owner shares it with the Share Authored capability. Another member needs a capability here plus a share. See Share an agent.
Create a Team¶
- In the organization sidebar, select Teams, then Create team. The team editor opens.
- Enter a Name, for example
Security operations. - In Members, choose at least one active member.
- In Roles, choose the roles the team holds.
- Select Create team. The toast says Team created.
Every member of the team inherits the team roles. You can also add a team to an invitation.
Next Step¶
Continue with Share an agent.