Skip to main content
When you build a Custom Role, you grant access by selecting individual permissions. This page documents what each permission controls so you can pick the least-privileged set that does the job. In the role builder, permissions are organized as feature area → capability → access level:
  • Feature area — the top-level group (Studio, Settings, Security, …).
  • Capability — a specific feature within that area (for example Users, Guardrails, Models).
  • Access level — what you can do with it. The common levels are:
    • Read — view only.
    • Manage — full write access (create, update, and delete).
    • Browse / View page — open the feature’s page or area in the UI, with no data changes.
    • A few areas use finer levels — for example Budgets uses All / Project / Your own scopes.
A user’s effective permissions are the union of every role assigned to them, directly or inherited from a group.
If a permission described here doesn’t appear in your role builder, it’s tied to a feature that isn’t enabled for your account yet. Contact your Airia representative if you need it.

Studio

Building, deploying, and operating agents, pipelines, models, tools, data sources, and related Studio assets.
CapabilityLevelWhat it grants
AdministrationReadAccess the System Agents settings — view system agents, enable/disable them, configure overrides, and pin/unpin versions (this single permission gates the whole System Agents area, including changes)
Agents & PipelinesReadList/view agents
Agents & PipelinesManageCreate, update, delete, execute, deploy, export, and version agents, and view feedback and requests
AssistantsReadView assistants
AssistantsManageCreate, update, and delete assistants
AttachmentsReadView/refresh attachment URLs
AttachmentsManageUpload and delete attachments
Code StepsExecuteExecute code steps in pipelines
DashboardReadView usage dashboard, top agents, models, and tools
Data Sources / ConnectorsReadView data sources
Data Sources / ConnectorsManageCreate, update, and delete data sources
DeploymentsReadView deployments
DeploymentsManageCreate, update, delete, pin/unpin deployments, manage API keys, and run batch operations
EvaluationsReadView evaluations
EvaluationsManageCreate, clone, and delete evaluations
Execution LogsReadView pipeline execution logs
Execution LogsManageDelete pipeline execution logs
FeedsConsumption / Conversation / Execution / Gateway / Ingestion / ProcessingView the corresponding activity and monitoring feed
InsightsReadView insights dashboard
JobsReadView jobs and results
JobsManageCreate, delete, and execute (rename/cancel/retry) jobs
Knowledge GraphsReadView knowledge graphs
Knowledge GraphsManageCreate, update, and delete knowledge graphs
MCP ServersReadView MCP servers available to attach to agents as tools
MCP ServersManageCreate, update, and delete MCP servers used as agent tools
MemoriesReadView memories
MemoriesManageCreate, update, and delete memories
ModelsReadView available models
ModelsManageAdd, update, and remove models
Model DeprecationReadView model deprecation banners
Model DeprecationManageDismiss banners and bulk replace deprecated models
ProjectsReadList/view projects
ProjectsManageCreate, update, delete, pin/unpin, and archive projects
PromptsReadView reusable prompt templates used when building agents
PromptsManageCreate, update, and delete reusable prompt templates
SchedulesReadView deployment schedules
SchedulesManageCreate, update, and delete deployment schedules
SkillsReadBrowse skills page and view skills repositories
SkillsManageCreate, update, and delete skills repositories
Smart ScanReadView smart scans
Smart ScanManageCreate, update, delete, and execute (retry/cancel) smart scans
Smart Scan TemplatesReadView SmartScan template groups
Smart Scan TemplatesManageCreate and delete SmartScan template groups
ToolsReadView tools
ToolsManageCreate, update, and delete tools
User PromptsReadView prompts saved by individual users
User PromptsManageCreate, update, and delete prompts saved by individual users
User TasksReadBrowse routines page and view user tasks and routines
User TasksManageCreate, update, and delete user tasks and routines

Gateway

AI Gateway and MCP Gateway configuration, monitoring, swarm, and resilience.
CapabilityLevelWhat it grants
AI GatewayReadView AI gateway configs
AI GatewayRead AllView all AI gateway configs across the tenant
AI GatewayAPI KeysManage gateway API keys
AI GatewayManageCreate, update, delete gateway configs, and manage gateway API keys
MCP GatewayReadView MCP gateway list
MCP GatewayManageCreate, update, and delete MCP gateway servers
MCP MonitoringReadView MCP monitoring
Analytics / MonitoringReadView gateway monitoring
Resilience RulesReadView resilience rules
Resilience RulesManageCreate, update, and delete resilience rules
Swarm ManagementReadView swarm config
Swarm ManagementManageCreate, update, and delete swarm config

Catalog

End-user catalog surfaces: chat spaces and enterprise search.
CapabilityLevelWhat it grants
Enterprise SearchReadUse enterprise search to find files across data store connectors
Chat SpacesReadView chat spaces
Chat SpacesManageCreate and update chat spaces
Enterprise Search appears in two places: this Catalog permission grants the end-user search experience (finding files across connectors). The Settings → Enterprise Search permission grants the admin configuration of that feature (connecting data sources, deploying the integration).

Common

Cross-cutting capabilities every user touches: profile, conversations, artifacts, files, voice, and agent execution.
CapabilityLevelWhat it grants
AgentsExecuteExecute an agent / pipeline (run a chat turn or job)
ArtifactsReadView artifacts
ArtifactsManageCreate and update artifacts
ConversationsManageCreate, update, and delete conversations
Document GenerationManageGenerate, convert, and process documents
OAuth ProvidersReadView own OAuth provider connection status
OAuth ProvidersManageAuthorize OAuth provider for user account
ProfileReadView own profile
ProfileManageUpdate own profile
RolesReadView available roles
Text-to-SpeechManageSynthesize text to speech
User FilesReadList and download user store files
User FilesManageUpload, rename, and delete user store files and folders
Voice ChatManageCreate voice chat sessions

Governance

AI governance: use cases, assessments, risk registry, frameworks, workflows, disclosures, and AI-asset inventory.
CapabilityLevelWhat it grants
AI AssetsReadView AI assets
AI AssetsManageCreate, update, and delete AI assets
AI Asset MetadataReadView AI asset metadata
AI Asset MetadataManageCreate, update, and delete AI asset metadata
AssessmentsReadView assessments
AssessmentsManageCreate, update, and delete assessments
DashboardReadView governance dashboard
DisclosuresReadView disclosures
DisclosuresManageCreate, update, and delete disclosures
FrameworksReadView governance frameworks
FrameworksManageCreate, update, and delete governance frameworks
Risk RegistryReadView risk registry
Risk RegistryManageCreate, update, and delete risk entries
Governance SettingsReadView governance settings
Governance SettingsManageUpdate governance settings and approver configuration
Use CasesReadView use cases
Use CasesManageCreate, update, and delete use cases
WorkflowsReadView governance workflows
WorkflowsManageCreate, update, and delete governance workflows

Security

Security and compliance: guardrails, constraints, red teaming, posture management, SASE, code scanning, the AI app catalog, and audit-entry suppression.
CapabilityLevelWhat it grants
AI App CatalogReadView AI app catalog
AI App CatalogManageBlock/unblock AI apps
AuditReadView suppressed audit entries
AuditManageSuppress audit log entries
Security CenterReadView security center
Security CenterManageManage security center configuration
Code ScannerReadView scan results
Code ScannerManageExecute scans
Agent ConstraintsReadView constraints
Agent ConstraintsManageCreate, update, and delete constraints
Endpoint Agent PoliciesManageManage endpoint agent security policies
FeedsCloudflare / Constraints / DLP / Events / Integration / Responsible AI / ViolationsView the corresponding security monitoring feed
GuardrailsView pageOpen the Guardrails page
GuardrailsReadView guardrails
GuardrailsManageCreate, update, and delete guardrails
Red TeamingReadView red team campaigns
Red TeamingManageCreate, delete, evaluate campaigns, and view/generate datasets
SASE IntegrationReadView Shadow AI configs
SASE IntegrationManageCreate, update, and delete Shadow AI configs
Security Posture ManagementReadView SPM dashboard
Security Posture ManagementManageCreate, update, delete, refresh, and connect SPM configs
Security → Audit controls audit-entry suppression (hiding entries from the audit log). To let a role view the tenant audit log instead, use Settings → Audit Logging → Read.

Community

Private community library: agents, submissions, memberships, invite codes, contributors, and sharing.
CapabilityLevelWhat it grants
AgentsReadBrowse the agent catalog in communities
CommunitiesReadBrowse private communities page and list/view communities the tenant is a member of
CommunitiesManageCreate, update, and delete communities
ContributorsReadView community contributors
ContributorsManageUpdate community contributors
Invite CodesReadView community invite codes
Invite CodesManageCreate and revoke community invite codes
MembershipsReadView member lists in communities
MembershipsManageInvite tenants, revoke, change roles, and accept/decline invites
SharingReadShare agents and resources with the community
SubmissionsReadView community submissions
SubmissionsReviewApprove or reject submissions
SubmissionsManageCreate, submit, review, approve, reject, and update submissions
UsersReadView community users
UsersManageCreate, update, and delete community users

Marketplace

Marketplace library, billing/subscriptions, and transactions.
CapabilityLevelWhat it grants
BillingReadView billing portal and subscription info
BillingSubscribeStart a new subscription / service-pack checkout via the paywall
BillingManageCreate payments and checkout sessions
LibraryReadView marketplace library (models, agents, prompts)
TransactionsReadView financial transactions and receipts

MCP

Model Context Protocol gateway: servers, analytics, and tenant access.
CapabilityLevelWhat it grants
AnalyticsReadView MCP analytics and usage
ServersReadBrowse the custom remote MCP servers page and view individual servers
ServersManageCreate, update, and delete custom remote MCP servers
Tenant AccessManageManage tenant server access
Three MCP surfaces, three permission groups: Studio → MCP Servers (Studio area above) attaches MCP servers to agents as tools; Gateway → MCP Gateway (Gateway area) is the hosted gateway that proxies and secures MCP traffic tenant-wide; MCP → Servers (here) registers the individual custom remote MCP servers exposed through that gateway.

Budgets

Budget management — viewing and updating company, project, and personal budgets.
CapabilityLevelWhat it grants
All budgetsBrowseNavigate through budget management views
All budgetsReadRead all budgets: company, project, user, or gateway
All budgetsUpdateUpdate all budgets: company, project, user, or gateway
Project budgetsReadRead budgets for projects you belong to
Project budgetsUpdateUpdate budgets for projects you belong to
Your own budgetReadRead your own budget
Your own budgetUpdateUpdate your own budget

Settings

Organization administration: users, groups, SSO/SCIM, credentials, API keys, branding, data retention, and other tenant settings.
CapabilityLevelWhat it grants
Account SettingsReadView tenant/account info
Account SettingsManageUpdate tenant/account settings
Airia AgentView pageOpen the Airia Agent settings page
API KeysReadList/view API keys
API KeysManageCreate, update, delete, and generate API keys and view key scopes
Audit LoggingReadView the tenant audit log
BrandingView pageOpen the Branding settings page
BrandingReadView branding config
BrandingManageCreate, update, and delete branding
Build with AIReadView config
Build with AIManageUpdate Build with AI config
ClassificationsView pageOpen the Classifications settings page
ClassificationsReadView classifications
ClassificationsManageCreate, update, and delete classifications
Cloud ConnectorReadView connected accounts
Cloud ConnectorManageConfigure connector groups
CredentialsView pageOpen the Credentials settings page
CredentialsReadList/view stored credentials (provider API keys, OAuth tokens, passwords)
CredentialsManageCreate, update, and delete stored credentials
Custom CredentialsView pageOpen the Custom Credentials settings page
Custom CredentialsReadList/view custom-type credentials (admin-defined fields, e.g. an API key sent as an HTTP header)
Custom CredentialsManageCreate, update, and delete custom-type credentials
Data RetentionReadView retention settings
Data RetentionManageUpdate retention settings
DepartmentsView pageOpen the Departments settings page
DepartmentsReadList departments
DepartmentsManageCreate, update, delete, and reorder departments
Enterprise SearchReadView search config
Enterprise SearchManageUpdate enterprise search config
ExtensionsReadView extensions
ExtensionsManageCreate, update, and delete extensions
External Identity ProviderReadView external IDP config
External Identity ProviderManageSave and validate external IDP config
External MonitoringReadView external OTEL monitoring data
GroupsReadList/view groups
GroupsManageCreate, update, delete, and bulk re-invite groups
ImpersonationReadView impersonation client
ImpersonationManageGenerate impersonation tokens
License KeysView pageOpen the License Keys settings page
License KeysReadList license keys
License KeysManageAdd and delete license keys
MeetingsView pageOpen the Meetings settings page
MeetingsReadView meeting config
MeetingsManageCreate, update, and delete meeting configs
NotificationsReadBrowse notifications page and view alerts and notification subscriptions
NotificationsManageSend, update, and close/archive notifications and alerts
OAuth ConnectorsView pageOpen the OAuth Connectors settings page
OAuth ConnectorsReadView OAuth connectors
OAuth ConnectorsManageCreate, update, and delete OAuth connectors
Omni AgentReadView OmniAgent configuration
Omni AgentManageUpdate OmniAgent configuration
PeopleView pageOpen the People page
Rate LimitsReadView rate limits
Rate LimitsManageUpdate rate limits
School DayReadOpen the School Day settings page
SIEMReadView SIEM settings
SIEMManageUpdate SIEM settings
SSO / Identity ProvidersReadView SSO configuration
SSO / Identity ProvidersManageAdd, update, delete, import identity providers, and generate SCIM tokens
Tenant ImagesReadView tenant images
Tenant ImagesManageUpload and delete tenant images
Tenant MetricsReadView tenant metrics
Tool EfficiencyReadView tool efficiency dashboard
UsersReadList/view users
UsersManageCreate, update, delete, re-invite users, assign roles/groups, reset passwords, and run batch operations
User SyncManageSync users and groups
WebhooksReadList/view webhooks
WebhooksManageCreate, update, and delete webhooks
Looking for how to create, edit, duplicate, or assign roles? See Custom Roles.