Roles and permissions

See what workspace admins, team managers and members can each see and do, and where team managers are limited to their own teams.

AgentWorks has three roles inside a workspace: workspace admin, team manager and member. A person's role decides which parts of the app and the Workspace console they can use. Your plan decides which features exist at all.

In the app the workspace admin role is labelled Admin. You see it in the role picker when you invite someone or change a role.

The three roles

RoleIn one line
Workspace admin (Admin)Full control of the organisation: people, teams, agents, balance, models, action policy and access.
Team managerManages their own team or teams: membership and what the team can use.
MemberUses what has been given to them, directly or through a team. No administration.

You can see the same summary in the app under What can each role do? on the People page.

What a workspace admin can do

  • Invite people, change roles, disable or delete users, and create teams. See People and teams.
  • Decide who can use which resources. See Access.
  • Choose models, switch features on or off, and manage notifications for everyone.
  • Manage the balance, plan, payment method and budgets. See Budgets and balance and Billing and plans.
  • Open Security & compliance, the audit log and API keys. See Security and API keys.

Only workspace admins see Billing & plan.

What a team manager can do

A team manager works inside the console, but only on the teams they manage. They see Overview, People, Access, Models and Budgets. They do not see General, Notifications, Features, Billing & plan, Security & compliance or API keys.

Within the teams they manage, a team manager can:

  • Add and remove team members, and change a person's role to or from Member.
  • Give the team access to resources, but only resources the manager can use themselves.
  • Choose which models the team can use. Models the workspace admin turned off are not listed.
  • Set monthly limits for the team and its people.
  • See runs, tasks, workflows, approvals and the activity feed of their team members, as well as their own and what is shared with them. They do not see the whole workspace.

A team manager cannot invite people directly. They propose a teammate and a workspace admin approves it. Teams need the Business or Enterprise plan.

What a member can do

A member uses the chat, and the agents, workflows, knowledge and connected apps that were shared with them or with their team. Members do not see the Workspace console. By default what a member creates stays private to them until they share it. See Sharing.

Whether a member can add money to the balance or set monthly limits is a setting per person (Money rights…). Admins always can. Adding money is off for everyone else until an admin allows it. Setting monthly limits is on by default for team managers and off for members; an admin can change either per person.

Admins and private work

Private until shared applies to admins too. A workspace admin does not automatically see agents or workflows that a member built and has not shared. An admin can still see who has access to what on the Access page.

Agency admins

An agency admin is the admin of the agency's own workspace and, in addition, uses the agency console to manage client workspaces. See Agency overview.