Grengin Cloud
Dashboard Soon Manage LLMs Soon Auth proxy & SSO Soon Team members Soon Community profile Soon Support tickets Soon
How-tos

I Made Them an Admin — Why Can’t They Use Jira in Chat?

This comes up a lot once you connect an app such as Jira, Google Drive, or Slack:

“I made them an admin. Why doesn’t the tool show up when they chat?”

Because those are two different keys.

  • Admin means they can help run Grengin — add people, change settings, connect apps.
  • Using a tool in chat means Grengin is allowed to call that app for them while they talk to the AI.

You can be an admin and still not have Jira in chat. You can also be a regular chat user and have Jira, if you turned it on for them.
We call the connected apps connectors. (In some docs you will also see MCP — that is just the technical name for the same thing.)
How to add a connector: Connectors.
How to choose who may use it: Connector Access.

Two screens, two jobs

Control Hub → Connectors is where you plug the app in (name, login, test, sync).
You need an admin role that includes managing connectors — often IT Admin. See Roles.
The shield icon on that connector is where you say who may use it in chat.
Open the connector, then the Access tab. That tab is the one that matters for “why doesn’t it show up?”
A common mistake: filling in the “default access” box on the add/edit form, and never opening the Access tab. The Access tab is the real control.

The three simple choices on Access

When you open the Access tab you pick a default:

Choice In everyday terms
All users Everyone in the company can use this connector in chat.
Admins only Only admins can use it. Regular chat users will not see it.
Explicit only Nobody, until you name who is allowed.

Use All users for something harmless, like looking up a public catalog.
Use Explicit only for anything that can create tickets, send email, or change files. That is the safer default while you are still learning.
You can then add exceptions:

  1. Click Add Rule.
  2. Choose Role, Department, or User — for example “the Support role,” “the Sales department,” or one person by name.
  3. For a department, you can include its sub-teams (that option is on by default).
  4. Choose Full, Read only, or Denied.
  5. Save the rule.

Denied is handy when almost everyone may use it, except one team.

One tool can be stricter than the rest

A connector often has several actions (we call them tools) — search, create, delete, and so on.
On the Tools tab you can leave them all following the server rules, or lock down one action. Example: everyone on Support may search Jira, but only two people may create tickets.
Click Sync Tools first if the list is empty. If you switch a tool back to “follow the server,” any custom rules on that tool are removed.
Step-by-step: Connector Access.

Ask this before you change someone’s role

  1. Do they need to connect or change apps for the whole company? → Give them an IT-style admin role.
  2. Do they only need to use Jira (or Drive) while chatting? → Leave them as a regular User, and allow them on that connector’s Access tab.
  3. Should a team lead share a tool with their own department, without becoming full IT? → That is what Department Admin is for. See Roles.

Making someone Super Admin so a missing tool appears is the wrong fix. You have given them the whole back office, when you only needed to open one app.

If the tool still doesn’t show up

Walk through this list in order:

  1. Is the connector turned on?
  2. Did you click Sync Tools at least once?
  3. What is default access? Explicit only with no rule means nobody sees it. Admins only means regular users will not see it.
  4. Is there a Denied rule for their role, team, or name?
  5. Does this one tool have tighter rules than the rest?
  6. If you allowed a department, are they actually in that department?
  7. Some apps ask each person to connect their own account. Others share one company connection. If it is “each person,” they still need to connect once. (Connectors)

If they cannot even open the Connectors page in Control Hub, that is a role issue — they are not an admin for connectors. How screens appear or hide: Access Control overview.
For the bigger picture of sign-in, admin roles, connectors, and teams, see How Access Works in Grengin: Who Can Sign In, Who Can Chat, and Who Can Manage.

Didn't solve it?

Open a support ticket — our team will pick it up within 1 business day.

Open a ticket