Scope

Permissions

A permission is a single allowed action on a specific area of the platform. Every permission belongs to a domain (the area it governs) and defines an action (what a user is allowed to do).

Grengin permissions list

Permissions are not assigned to users directly — they are bundled into roles, which are then assigned to users.

In Control Hub → Access Control → Permissions, you can browse the full permission catalog. This tab is a reference only; permissions are granted through roles.


Scope

Every permission has a fixed scope type shown as Global or Department in the UI:

ScopeMeaning
GlobalApplies across the entire platform. A global grant covers all departments with no restriction.
DepartmentCan be limited to one or more specific departments per user. The same permission can apply differently for different users.

Scope is a property of the permission — you do not configure it on the permission itself. For department-scoped permissions, set the department restriction per user when they are assigned to a role. From Access Control → Roles, expand the role’s user list and use Manage scoping to add departments or Assign all departments for full coverage.

View vs action permissions

Most domains separate View (read access to a Control Hub page or data) from action permissions such as Manage, Allocate, or Assign (create, edit, delete, or configure). Users typically need the View permission to reach a page; action permissions unlock controls on that page.


Permission reference

AI Platform

Governs configuration and visibility of AI engines and models.

ActionDescriptionScope
ViewView AI engine configurationsGlobal
ManageConfigure AI engines and modelsGlobal

Analytics

Governs access to usage analytics and reporting.

ActionDescriptionScope
ViewView usage analytics and reportsDepartment

Overview dashboard: The Control Hub Overview page requires global Analytics: View — department-scoped analytics access alone does not unlock Overview.


Audit Logs

Governs access to the platform audit trail.

ActionDescriptionScope
ViewView audit logsGlobal

Budget

Governs visibility and control over department budgets.

ActionDescriptionScope
ViewView budget allocations and usageDepartment
AllocateAllocate and adjust department budgetsDepartment

Departments

Governs visibility and management of the department structure.

ActionDescriptionScope
ViewView department structure and membersDepartment
ManageCreate, edit, and manage departmentsDepartment

MCP Servers

Governs access to MCP server configuration and delegation. In the Control Hub this area appears as Connectors.

ActionDescriptionScope
ViewView MCP server configurationsGlobal
AdminManage MCP server settings and deploymentsGlobal
DelegateDelegate MCP server access to departmentsDepartment

Roles

Governs who can view, create, and assign roles.

ActionDescriptionScope
ViewView roles and their configurationsGlobal
ManageCreate, edit, and delete rolesGlobal
AssignAssign roles to users and manage department scopingDepartment

Roles: View opens the Access Control page. Roles: Manage is required to create, edit, or delete custom roles. Roles: Assign is required to add or remove users from roles and to configure department scoping.


SSO Providers

Governs configuration of Single Sign-On integrations. In the Control Hub this area appears under Settings.

ActionDescriptionScope
ViewView SSO provider configurationsGlobal
ManageConfigure and manage SSO providersGlobal

System

Governs platform-level maintenance operations on the host system.

ActionDescriptionScope
MaintainReconfigure the host system (domain, TLS, and application updates)Global

Users

Governs visibility and management of user accounts.

ActionDescriptionScope
ViewView user profiles and detailsDepartment
ManageCreate, edit, and deactivate usersDepartment

All permissions at a glance

DomainActionScope
AI PlatformViewGlobal
AI PlatformManageGlobal
AnalyticsViewDepartment
Audit LogsViewGlobal
BudgetViewDepartment
BudgetAllocateDepartment
DepartmentsViewDepartment
DepartmentsManageDepartment
MCP ServersViewGlobal
MCP ServersAdminGlobal
MCP ServersDelegateDepartment
RolesViewGlobal
RolesManageGlobal
RolesAssignDepartment
SSO ProvidersViewGlobal
SSO ProvidersManageGlobal
SystemMaintainGlobal
UsersViewDepartment
UsersManageDepartment

  • Access Control overview — how permissions and roles fit together in the Control Hub.
  • Roles — system and custom roles that bundle these permissions.