Grengin Cloud
Dashboard Soon Manage LLMs Soon Auth proxy & SSO Soon Team members Soon Community profile Soon Support tickets Soon
How-tos

How Access Works in Grengin: Who Can Sign In, Who Can Chat, and Who Can Manage

If you just set up Grengin, the first puzzle is usually this: my teammate can chat, but they can’t see the same screens I can. That is normal. Grengin is built so most people only get the chat app, and a smaller group gets the admin area.

Think of it like an office. Everyone can use the lobby (chat). Only some people have keys to the back office (Control Hub). And even in the back office, the finance keys are different from the IT keys.

This post is the simple picture. When you are ready to click through the screens, the docs are linked at the end.

Four separate questions

Grengin does not have one “access” switch. It asks four different questions:

1. Can they sign in at all?
That is your company login (Google, Microsoft, and so on). You choose which email domains are allowed — for example only @yourcompany.com. Signing in does not make someone an admin. It just lets them into chat.

How to set this up: Single Sign-On.

2. Can they open the admin area?
The admin area is called Control Hub. You open it from your name at the bottom of the sidebar. Most people will never see that link — and that is what you want.

Who sees what in Control Hub is decided by roles. A role is a job title inside Grengin, such as Super Admin, Finance Admin, or User. You give a person a role; you do not tick permissions one by one.

The full explanation is in How Access & Permissions Work.

3. Can they use extra tools in chat?
Grengin can connect to apps you already use — Jira, Google Drive, and others. We call these connectors. Being an admin does not automatically turn those tools on for everyone. You choose who may use each one.

That is a separate setting, covered in the next community post and in Connector Access.

4. Which team are they on?
Departments are your company structure inside Grengin — Sales, Finance, Engineering. You can give a team its own budget, and you can limit which AI models that team may use.

How to set teams up: Organization & Departments.

A role is a job, not a pile of checkboxes

You will see two words in Control Hub: permissions and roles.

  • A permission is one small ability, like “view budgets” or “add users.”
  • A role is a bundle of those abilities with a name you recognize.

You always give someone a role. Grengin already includes ready-made roles (Super Admin, IT Admin, Finance Admin, HR Admin, Department Admin, Observer, and User). For most new teams, those are enough.

Two extra ideas, in plain language:

  • Look vs change. Someone can open a page and still not be able to edit it. That is on purpose. “View” means they can see it. “Manage” means they can change it.
  • This team only. Some roles can be limited to one department. A Sales manager should see Sales, not necessarily Finance. After you add them to a role, use Manage scoping to pick their teams.

Ready-made roles, and how to make your own: Roles.
Full list of abilities: Permissions.

What people will actually notice

What they tell you What it usually means
“I don’t see Control Hub.” They are a regular chat user. Give them an admin role only if they should manage the workspace.
“I can open the page but there is no Save button.” They can look, not change. They need a role that includes managing, not only viewing.
“I get Access denied.” They opened a link they are not allowed to use. The message is: “You do not have permission to view this page.”
“They can chat, but Jira never appears.” That is a connector setting, not a missing admin role.

Everyday chat (for people who are not admins) is in the User Guide.

A simple order to set things up

Do this before you invite the whole company:

  1. Turn on company login and allow only your company’s email domain. (SSO)
  2. Create a few departments that match how you already work. (Organization)
  3. Keep Super Admin for one or two people. Give everyone else a ready-made role that matches their real job. (Roles)
  4. If you connect Jira, Drive, or similar, decide who may use it in chat — separately from who is an admin. (Connector Access)
  5. Set a budget and, if you want, which AI models each department may use.
  6. Invite the rest of the team as regular users.

For “who should get which role on day one,” see Who Should Be an Admin? A Simple Starter Guide.

Want the click-by-click version?

Topic Docs
How Control Hub shows or hides screens Access Control overview
Ready-made roles Roles
Every permission, if you need it Permissions
Connecting apps like Jira or Drive Connectors
Who may use those apps in chat Connector Access
Teams, budgets, and models Organization & Departments
Company login SSO
Didn't solve it?

Open a support ticket — our team will pick it up within 1 business day.

Open a ticket