Permissions
A permission is a single allowed action on a specific area of the platform. Every permission belongs to a domain (the area it governs) and defines an action (what a user is allowed to do).
Permissions are not assigned to users directly — they are bundled into roles, which are then assigned to users.
In Control Hub → Access Control → Permissions, you can browse the full permission catalog. This tab is a reference only; permissions are granted through roles.
Scope
Every permission has a fixed scope type shown as Global or Department in the UI:
| Scope | Meaning |
|---|---|
| Global | Applies across the entire platform. A global grant covers all departments with no restriction. |
| Department | Can be limited to one or more specific departments per user. The same permission can apply differently for different users. |
Scope is a property of the permission — you do not configure it on the permission itself. For department-scoped permissions, set the department restriction per user when they are assigned to a role. From Access Control → Roles, expand the role’s user list and use Manage scoping to add departments or Assign all departments for full coverage.
View vs action permissions
Most domains separate View (read access to a Control Hub page or data) from action permissions such as Manage, Allocate, or Assign (create, edit, delete, or configure). Users typically need the View permission to reach a page; action permissions unlock controls on that page.
Permission reference
AI Platform
Governs configuration and visibility of AI engines and models.
| Action | Description | Scope |
|---|---|---|
| View | View AI engine configurations | Global |
| Manage | Configure AI engines and models | Global |
Analytics
Governs access to usage analytics and reporting.
| Action | Description | Scope |
|---|---|---|
| View | View usage analytics and reports | Department |
Overview dashboard: The Control Hub Overview page requires global Analytics: View — department-scoped analytics access alone does not unlock Overview.
Audit Logs
Governs access to the platform audit trail.
| Action | Description | Scope |
|---|---|---|
| View | View audit logs | Global |
Budget
Governs visibility and control over department budgets.
| Action | Description | Scope |
|---|---|---|
| View | View budget allocations and usage | Department |
| Allocate | Allocate and adjust department budgets | Department |
Departments
Governs visibility and management of the department structure.
| Action | Description | Scope |
|---|---|---|
| View | View department structure and members | Department |
| Manage | Create, edit, and manage departments | Department |
MCP Servers
Governs access to MCP server configuration and delegation. In the Control Hub this area appears as Connectors.
| Action | Description | Scope |
|---|---|---|
| View | View MCP server configurations | Global |
| Admin | Manage MCP server settings and deployments | Global |
| Delegate | Delegate MCP server access to departments | Department |
Roles
Governs who can view, create, and assign roles.
| Action | Description | Scope |
|---|---|---|
| View | View roles and their configurations | Global |
| Manage | Create, edit, and delete roles | Global |
| Assign | Assign roles to users and manage department scoping | Department |
Roles: View opens the Access Control page. Roles: Manage is required to create, edit, or delete custom roles. Roles: Assign is required to add or remove users from roles and to configure department scoping.
SSO Providers
Governs configuration of Single Sign-On integrations. In the Control Hub this area appears under Settings.
| Action | Description | Scope |
|---|---|---|
| View | View SSO provider configurations | Global |
| Manage | Configure and manage SSO providers | Global |
System
Governs platform-level maintenance operations on the host system.
| Action | Description | Scope |
|---|---|---|
| Maintain | Reconfigure the host system (domain, TLS, and application updates) | Global |
Users
Governs visibility and management of user accounts.
| Action | Description | Scope |
|---|---|---|
| View | View user profiles and details | Department |
| Manage | Create, edit, and deactivate users | Department |
All permissions at a glance
| Domain | Action | Scope |
|---|---|---|
| AI Platform | View | Global |
| AI Platform | Manage | Global |
| Analytics | View | Department |
| Audit Logs | View | Global |
| Budget | View | Department |
| Budget | Allocate | Department |
| Departments | View | Department |
| Departments | Manage | Department |
| MCP Servers | View | Global |
| MCP Servers | Admin | Global |
| MCP Servers | Delegate | Department |
| Roles | View | Global |
| Roles | Manage | Global |
| Roles | Assign | Department |
| SSO Providers | View | Global |
| SSO Providers | Manage | Global |
| System | Maintain | Global |
| Users | View | Department |
| Users | Manage | Department |
Related
- Access Control overview — how permissions and roles fit together in the Control Hub.
- Roles — system and custom roles that bundle these permissions.