Permissions

Organization permissions use resource:action names. Roles combine these permissions; Access Control explains how roles and resource grants work together.

Predefined Roles

Built-in roles cannot be edited or deleted.

Admin

Full access to all resources including user management, roles, and platform settings

The admin role has all permissions on every resource.

Platform Admin

Runs the platform — everything an admin can do, except reading other users' logs, reading the audit log, and impersonating users

Platform Admin holds all permissions except log:admin, auditLog:admin, openappaDiagnostics:admin, and member:impersonate — so holders run the platform (users, roles, settings, resources) while other members' LLM/MCP logs, the org-wide audit trail, and impersonation stay out of reach. They keep log:read and auditLog:read, which show their own records only. Combined with the no-privilege-escalation rule, a Platform Admin cannot grant themselves or anyone else a role carrying the withheld permissions.

Editor

Full access to core resources, but cannot change organization settings or manage users, roles, or identity providers

ResourceActions
Agentsread, create, delete
Skillsread, create, delete
Pluginsread, create, update, delete
Appsread, create
Scheduled Tasksread, create, update, delete
LLM Proxyread, update
LLM Provider API Keysread, create
LLM Virtual Keysread, create
LLM OAuth Clientsread, create
LLM Modelsread, update
LLM Limitsread, create, update, delete
LLM Cost Analyticsread
MCP Gatewaysread, create, delete
MCP OAuth Clientsread, create
Tools & Policiesread, create, update, delete
MCP Registryread, create
MCP Server Installationsread, create, update, delete
Environmentsread, create, update, delete
Credentialsread, create, update, delete
OpenAPPA Policyread, update
OpenAPPA Diagnosticsread, update
Knowledge Sourcesread, create, update, delete, query
Chatsread, create, update, delete, full-view
Projectsread, create, update, delete
LLM & MCP Logsread
API Keysread, create, delete
Usersread
Rolesread
Teamsread
Identity Providersread

Member

Can manage agents, tools, and chat, with read-only access to most other resources

ResourceActions
Agentsread, create, delete
Skillsread, create, delete
Appsread, create
Scheduled Tasksread, create, update, delete
LLM Proxyread
LLM Provider API Keysread
LLM Virtual Keysread, create
LLM OAuth Clientsread
LLM Modelsread
MCP Gatewaysread, create, delete
MCP OAuth Clientsread
Tools & Policiesread
MCP Registryread
MCP Server Installationsread, create, delete
Environmentsread
Credentialsread
OpenAPPA Policyread
Knowledge Sourcesread, query
Chatsread, create, update, delete, full-view
Projectsread, create, update, delete
API Keysread, create, delete
Teamsread

Available Permissions

These permissions can be selected in custom roles. Per-resource actions and scopes are described under Granular Access Control.

PermissionDescription
ac:readView custom roles and their permissions
ac:createCreate new custom roles
ac:updateModify custom role permissions
ac:deleteDelete custom roles
accessPolicies:readView access policies for all resource types
accessPolicies:updateEdit access policies and grant access across all resource types
agent:readOpen Agents, and use the code sandboxes and files of agents you can use
agent:createCreate new agents
agent:deleteOpen the trash of deleted agents
apiKey:readView API keys
apiKey:createCreate API keys
apiKey:deleteDelete API keys
app:readOpen Apps
app:createCreate new MCP Apps
auditLog:readView audit log records of your own administrative actions
auditLog:adminView every audit event in your organization (also requires Read)
chat:readView and access chat conversations
chat:createStart new chat conversations
chat:updateEdit chat messages and conversation settings
chat:deleteDelete chat conversations
chat:full-viewShow the full chat: the agent picker, model and API key selectors, and expandable tool calls. Without it, chat shows a simpler view
credential:readView saved credentials
credential:createCreate saved credentials
credential:updateModify saved credentials
credential:deleteDelete saved credentials
environment:readView and list deployment environments
environment:createCreate deployment environments
environment:updateModify deployment environments, including the org default environment
environment:deleteDelete deployment environments
identityProvider:readView identity provider configurations (SSO)
identityProvider:createSet up new identity providers
identityProvider:updateModify identity provider settings
identityProvider:deleteRemove identity providers
knowledgeSource:readView Knowledge Bases and Connectors
knowledgeSource:createCreate Knowledge Bases and Connectors
knowledgeSource:updateModify Knowledge Bases and Connectors
knowledgeSource:deleteDelete Knowledge Bases and Connectors, view the deleted ones, and restore them
knowledgeSource:queryQuery knowledge sources for information retrieval
llmCost:readView organization-wide LLM usage cost statistics and analytics
llmLimit:readView token usage limits
llmLimit:createCreate new usage limits
llmLimit:updateModify existing usage limits
llmLimit:deleteRemove usage limits
llmModel:readView synced LLM models and capabilities
llmModel:updateSync the model catalog and see every model, including ones not shared with you
llmOauthClient:readOpen LLM OAuth client registrations
llmOauthClient:createCreate LLM OAuth client registrations
llmProviderApiKey:readOpen LLM provider API keys
llmProviderApiKey:createAdd new LLM provider API keys
llmProxy:readView the LLM Proxy and its connection details
llmProxy:updateModify LLM Proxy configuration
llmVirtualKey:readOpen LLM virtual keys
llmVirtualKey:createCreate LLM virtual keys
log:readView your own LLM proxy and MCP tool call logs in the active organization
log:adminView every LLM and MCP log in your organization (also requires Read)
mcpGateway:readOpen MCP Gateways
mcpGateway:createCreate new MCP gateways
mcpGateway:deleteOpen the trash of deleted MCP gateways
mcpOauthClient:readOpen MCP OAuth client registrations
mcpOauthClient:createCreate MCP OAuth client registrations
mcpRegistry:readOpen the MCP registry and use its built-in servers
mcpRegistry:createAdd servers to the MCP registry
mcpServerInstallation:readView installed MCP servers and their status
mcpServerInstallation:createInstall MCP servers from the registry
mcpServerInstallation:updateModify installed MCP server configuration
mcpServerInstallation:deleteUninstall, view deleted, and restore MCP servers within your access
member:readView organization members and their roles
member:createAdd new members to the organization and manage invitations
member:updateChange member roles and settings
member:deleteRemove members from the organization
member:impersonateTemporarily sign in as another member to see the app with their access (role debugging)
openappaDiagnostics:readRead all organization yells and your own consult logs
openappaDiagnostics:updateResolve and reopen organization yells
openappaDiagnostics:adminRead consult logs across the organization
openappaPolicy:readView OpenAPPA policy, batteries, and coverage
openappaPolicy:updateValidate and edit OpenAPPA policy and manage batteries
organizationSettings:readView every organization settings page, including messaging channels
organizationSettings:updateChange organization settings, messaging channels, and site notifications
plugin:readView plugins and their file metadata
plugin:createCreate plugins
plugin:updateModify plugin metadata and files
plugin:deleteDelete plugins
project:readView projects and your own sessions inside them
project:createCreate projects
project:updateEdit project descriptions, instructions, and sharing
project:deleteDelete projects
scheduledTask:readView scheduled tasks and their run history
scheduledTask:createCreate new scheduled tasks and trigger runs
scheduledTask:updateModify scheduled task configuration
scheduledTask:deleteDelete scheduled tasks
serviceAccount:readOpen Service Accounts
serviceAccount:createCreate service accounts
skill:readOpen Skills
skill:createCreate new agent skills
skill:deletePermanently delete skills from the trash
team:readView teams and their members
team:createCreate new teams
team:updateModify team settings
team:deleteDelete teams
toolPolicy:readView tools, tool invocation policies, and trusted data policies
toolPolicy:createRegister tools and create security policies
toolPolicy:updateModify tools, tool configuration, and security policies
toolPolicy:deleteRemove tools and security policies

LLM API Permissions

API dataRequired permissionsVisibility
View LLM Proxy configurationllmProxy:readThe active organization's proxy and connection details
Update LLM Proxy configurationllmProxy:updateThe active organization's proxy configuration
Personal usage (/api/statistics/me*)NoneThe caller's usage
Cost totals, teams, agents, models, and savingsllmCost:readAll matching usage in the active organization
User cost statistics (/api/statistics/users)llmCost:readThe caller's usage
User cost statistics for all usersllmCost:read and member:readIdentified users in the active organization
App cost statisticsllmCost:read and app:readApps allowed by the caller’s read grants
Skill cost statisticsllmCost:read and skill:readSkills allowed by the caller’s read grants
LLM and MCP logs for the callerlog:readRecords attributed to the caller
All LLM and MCP logslog:read and log:adminAll records in the active organization, including unattributed traffic

Service accounts use their assigned role for these APIs. A service account has no personal usage or caller-attributed log rows. Grant llmCost:read for organization-wide cost exports. Grant both log:read and log:admin for organization-wide log exports. Add member:read to include per-user cost statistics.