- Feature area — the top-level group (Studio, Settings, Security, …).
- Capability — a specific feature within that area (for example Users, Guardrails, Models).
- Access level — what you can do with it. The common levels are:
- Read — view only.
- Manage — full write access (create, update, and delete).
- Browse / View page — open the feature’s page or area in the UI, with no data changes.
- A few areas use finer levels — for example Budgets uses All / Project / Your own scopes.
A user’s effective permissions are the union of every role assigned to them, directly or inherited from a group.
If a permission described here doesn’t appear in your role builder, it’s tied to a feature that isn’t enabled for your account yet. Contact your Airia representative if you need it.
Studio
Building, deploying, and operating agents, models, tools, data sources, and related Studio assets.Gateway
AI Gateway and MCP Gateway configuration, monitoring, swarm, and resilience.Catalog
End-user catalog surfaces: chat spaces and enterprise search.Enterprise Search appears in two places: this Catalog permission grants the end-user search experience (finding files across connectors). The Settings → Enterprise Search permission grants the admin configuration of that feature (connecting data sources, deploying the integration).
Common
Cross-cutting capabilities every user touches: profile, conversations, artifacts, files, voice, and agent execution.Roles → Read is managed automatically for custom roles. Airia adds and locks this permission on any custom role that grants admin-level permissions — which makes the role admin-tier, so its assigned users land on the admin home page instead of the chat/catalog experience. End-user-tier roles (only end-user-level permissions) don’t receive it. You don’t grant it by hand; a role’s tier follows the permissions you select. See Mandatory baseline permissions for the permissions every custom role is required to hold.
Governance
AI governance: use cases, assessments, risk registry, frameworks, workflows, disclosures, and AI-asset inventory.Security
Security and compliance: guardrails, constraints, red teaming, posture management, SASE, code scanning, the AI app catalog, and audit-entry suppression.Security → Audit controls audit-entry suppression (hiding entries from the audit log). To let a role view the account system log instead, use Settings → System Log → Read.
Community
Private community library: agents, submissions, memberships, invite codes, contributors, and sharing.Marketplace
Marketplace library, billing/subscriptions, and transactions.MCP
Model Context Protocol gateway: servers, analytics, and tenant access.Three MCP surfaces, three permission groups: Studio → MCP Servers (
Studio area above) attaches MCP servers to agents as tools; Gateway → MCP Gateway (Gateway area) is the hosted gateway that proxies and secures MCP traffic account-wide; MCP → Servers (here) registers the individual custom remote MCP servers exposed through that gateway.Budgets
Budget management — viewing and updating company, project, and personal budgets.Settings
Organization administration: users, groups, SSO/SCIM, credentials, API keys, branding, data retention, and other account settings.Looking for how to create, edit, duplicate, or assign roles? See Custom Roles.
