Grengin Cloud
Dashboard Soon Manage LLMs Soon Auth proxy & SSO Soon Team members Soon Community profile Soon Support tickets Soon
How-tos

Who Should Be an Admin? A Simple Starter Guide

When you first open Grengin, you are a Super Admin. That is how setup works — someone has to have every key.

The next step is not “make the whole company Super Admin so nothing gets blocked.” Most people only need chat. A few people need a specific admin job. Grengin already has ready-made roles for those jobs.

This post is a day-one guide. The exact list of what each role can do is in Roles.

Ready-made roles (you do not have to invent these)

In Control Hub, go to Access Control → Roles. The ones marked (System) came with Grengin. You can add people to them. You cannot rename them, delete them, or change what they include — and Super Admin cannot be edited at all.

Role Give it to In one sentence
Super Admin One or two people you trust with everything The emergency key. Keep it rare.
IT Admin Whoever connects login, AI models, and apps like Jira They run the technical setup, not people or budgets.
Finance Admin Whoever watches spend and sets team budgets They see cost. They do not manage logins.
HR Admin Whoever adds people and puts them on teams They manage people. They do not run IT.
Department Admin A manager of one team (or a few teams) They look after their own group — people, budget, and sharing tools with that group.
Observer Someone who should look, not change Read-only. Good for leadership or audit.
User Almost everyone Chat only. No Control Hub. This is the default, and that is a good thing.

IT and HR are opposites on purpose. The person who connects Microsoft login should not automatically be the person who can change everyone’s budget.

Limit a manager to their own team

This is the step that is easy to skip.

If you make someone Department Admin and stop there, Grengin does not always know which department you meant. After you add them to the role:

  1. Open the role and expand Users with this role.
  2. Click Manage scoping next to their name.
  3. Pick their departments. Only choose Assign all departments if they should really see the whole company.

Do the same for Finance Admin or HR Admin unless they truly work company-wide.

More on “this team only” vs “the whole company”: Access Control overview.

When you might make your own role

Use a custom role when a ready-made one is almost right but a bit too much. Examples:

  • Someone who only maintains shared prompts
  • Someone who only looks at activity history
  • Someone who only manages company login, not the rest of IT

How to create that role: Roles (the “Custom roles” section). A person can have more than one role. Prefer two small jobs over one role that does everything.

Before you invite the whole company

  1. Turn on company login. Allow only your company’s email domain. Only auto-create accounts for domains you fully trust. (SSO)
  2. Create a few departments that match real teams. Put a couple of people in them to try it. (Organization)
  3. Keep Super Admin to one or two accounts. Give IT / Finance / HR / Department Admin / Observer only to people who have that job in real life.
  4. Use Manage scoping so a department manager cannot see every other team.
  5. If you connect Jira, Drive, or similar, decide who may use it in chat. Do not promote people to Super Admin just to make a tool appear. (Connector Access)
  6. Set a budget for each department if you care about spend. You can also limit which AI models a team may use. An empty model list means all models, not none.
  7. Invite everyone else as User. Add an admin role later, when they actually need one.

If it feels broken, it is often working

They say Usually means
“I can’t sign in.” Their email domain is not allowed, or new accounts are not created automatically. SSO
“I don’t see Control Hub.” They are a regular User. Add an admin role only if they should help run Grengin.
“I can see the page but I can’t change anything.” They can look, not edit. That is a different ability.
“Our manager sees the wrong teams.” Manage scoping was skipped, or set to all departments.
“The Jira button never appears in chat.” That is a connector setting, not a missing admin role. See I Made Them an Admin — Why Can’t They Use Jira in Chat?

For the simple picture of sign-in, admin roles, connectors, and teams, see How Access Works in Grengin: Who Can Sign In, Who Can Chat, and Who Can Manage.

Didn't solve it?

Open a support ticket — our team will pick it up within 1 business day.

Open a ticket