System roles

Roles

A role is a named collection of permissions assigned to one or more users. Instead of granting permissions individually, you bundle them into a role and assign that role to users. A user’s access is the combined set of all permissions across every role they hold.

Manage roles from Control Hub → Access Control → Roles.

Grengin roles list

There are two types of roles: system roles and custom roles.


System roles

System roles are predefined by grengin. They cannot be deleted and their permissions cannot be modified — they represent standard access patterns for common organizational responsibilities. System roles are labeled (System) in the UI.

What you can doWhat you cannot do
Add or remove users (with Roles: Assign)Add or remove permissions from the role
Update department scope per user via Manage scopingDelete the role or rename system roles
View permissions included in the roleEdit permissions on system roles

Grengin ships with seven system roles:

RolePurpose
Super AdminFull access to every part of the platform
IT AdminManage AI infrastructure, MCP servers, SSO, and system maintenance
Finance AdminManage budgets and view financial analytics
HR AdminManage users, departments, and role assignments
Department AdminManage a department’s people, budget, and MCP server access
ObserverRead-only visibility into users, departments, and analytics
UserNo Control Hub access — standard grengin chat user

Super Admin is protected in the UI — it cannot be edited or deleted.


Super Admin

Full platform access. Super Admins can configure every part of grengin, manage all users and roles, and perform system-level operations. Assign this role sparingly.

DomainActionScope
AI PlatformManageGlobal
AI PlatformViewGlobal
AnalyticsViewDepartment
Audit LogsViewGlobal
BudgetViewDepartment
BudgetAllocateDepartment
DepartmentsViewDepartment
DepartmentsManageDepartment
MCP ServersViewGlobal
MCP ServersAdminGlobal
MCP ServersDelegateDepartment
RolesViewGlobal
RolesManageGlobal
RolesAssignDepartment
SSO ProvidersViewGlobal
SSO ProvidersManageGlobal
SystemMaintainGlobal
UsersViewDepartment
UsersManageDepartment

IT Admin

Covers grengin’s technical infrastructure — AI engines, MCP servers, SSO integrations, and system maintenance. IT Admins have no access to user management, budgets, or org structure.

DomainActionScope
AI PlatformManageGlobal
MCP ServersViewGlobal
MCP ServersAdminGlobal
MCP ServersDelegateDepartment
SSO ProvidersViewGlobal
SSO ProvidersManageGlobal
SystemMaintainGlobal

Finance Admin

Scoped to financial operations. Finance Admins can view and allocate budgets, monitor analytics, and view department structure — but cannot manage users, roles, or platform configuration.

DomainActionScope
AnalyticsViewDepartment
BudgetViewDepartment
BudgetAllocateDepartment
DepartmentsViewDepartment

HR Admin

Focused on people and org management. HR Admins can manage users and departments, view roles, and assign roles to users — but have no access to budgets, analytics, or platform configuration.

DomainActionScope
DepartmentsViewDepartment
RolesViewGlobal
RolesAssignDepartment
UsersViewDepartment
UsersManageDepartment

Department Admin

Designed for managers who own a specific department. Department Admins can manage their department’s members, budgets, and MCP server delegation. When assigning this role, restrict department-scoped permissions to the relevant departments via Manage scoping.

DomainActionScope
AnalyticsViewDepartment
BudgetViewDepartment
BudgetAllocateDepartment
DepartmentsViewDepartment
DepartmentsManageDepartment
MCP ServersDelegateDepartment
UsersViewDepartment
UsersManageDepartment

Observer

Read-only access to users, departments, and analytics. Observers can see what is happening but cannot take actions or modify anything.

DomainActionScope
AnalyticsViewDepartment
DepartmentsViewDepartment
UsersViewDepartment

User

No permissions. This is the default role for standard grengin chat users who do not need Control Hub access. Users with only this role will not see the Control Hub link and cannot access it.


Custom roles

Custom roles let you define access patterns beyond the system roles. Create as many as needed and change them at any time.

What you can do
Create a role with any name
Add or remove any permissions
Add or remove users (with Roles: Assign)
Update department scope per user via Manage scoping
Edit or delete the role (with Roles: Manage)

Create a custom role

Grengin add new role
  1. Go to Control Hub → Access Control → Roles.
  2. Click Add new role (requires Roles: Manage).
  3. Enter a role name.
  4. Select permissions from the grouped checklist. Use Select all or Clear within each domain as needed.
  5. Click Create role.

Assign users and configure scope

Grengin assign role
  1. On the role card, click Add user (requires Roles: Assign).
  2. Search for and select the user.
  3. For department-scoped permissions, expand Users with this role, then click Manage scoping next to the user.
  4. Assign specific departments, or choose Assign all departments for unrestricted access within that role’s department-scoped permissions.

Edit or remove a custom role

  • Edit role — change the name or permission set (requires Roles: Manage).
  • Delete role — permanently removes the role; users lose its permissions (requires Roles: Manage).