Permissions
Organization permissions use resource:action names. Roles combine these permissions; Access Control explains how roles and resource grants work together.
Predefined Roles
Built-in roles cannot be edited or deleted.
Admin
Full access to all resources including user management, roles, and platform settings
The admin role has all permissions on every resource.
Platform Admin
Runs the platform — everything an admin can do, except reading other users' logs, reading the audit log, and impersonating users
Platform Admin holds all permissions except log:admin, auditLog:admin, openappaDiagnostics:admin, and member:impersonate — so holders run the platform (users, roles, settings, resources) while other members' LLM/MCP logs, the org-wide audit trail, and impersonation stay out of reach. They keep log:read and auditLog:read, which show their own records only. Combined with the no-privilege-escalation rule, a Platform Admin cannot grant themselves or anyone else a role carrying the withheld permissions.
Editor
Full access to core resources, but cannot change organization settings or manage users, roles, or identity providers
| Resource | Actions |
|---|---|
| Agents | read, create, delete |
| Skills | read, create, delete |
| Plugins | read, create, update, delete |
| Apps | read, create |
| Scheduled Tasks | read, create, update, delete |
| LLM Proxy | read, update |
| LLM Provider API Keys | read, create |
| LLM Virtual Keys | read, create |
| LLM OAuth Clients | read, create |
| LLM Models | read, update |
| LLM Limits | read, create, update, delete |
| LLM Cost Analytics | read |
| MCP Gateways | read, create, delete |
| MCP OAuth Clients | read, create |
| Tools & Policies | read, create, update, delete |
| MCP Registry | read, create |
| MCP Server Installations | read, create, update, delete |
| Environments | read, create, update, delete |
| Credentials | read, create, update, delete |
| OpenAPPA Policy | read, update |
| OpenAPPA Diagnostics | read, update |
| Knowledge Sources | read, create, update, delete, query |
| Chats | read, create, update, delete, full-view |
| Projects | read, create, update, delete |
| LLM & MCP Logs | read |
| API Keys | read, create, delete |
| Users | read |
| Roles | read |
| Teams | read |
| Identity Providers | read |
Member
Can manage agents, tools, and chat, with read-only access to most other resources
| Resource | Actions |
|---|---|
| Agents | read, create, delete |
| Skills | read, create, delete |
| Apps | read, create |
| Scheduled Tasks | read, create, update, delete |
| LLM Proxy | read |
| LLM Provider API Keys | read |
| LLM Virtual Keys | read, create |
| LLM OAuth Clients | read |
| LLM Models | read |
| MCP Gateways | read, create, delete |
| MCP OAuth Clients | read |
| Tools & Policies | read |
| MCP Registry | read |
| MCP Server Installations | read, create, delete |
| Environments | read |
| Credentials | read |
| OpenAPPA Policy | read |
| Knowledge Sources | read, query |
| Chats | read, create, update, delete, full-view |
| Projects | read, create, update, delete |
| API Keys | read, create, delete |
| Teams | read |
Available Permissions
These permissions can be selected in custom roles. Per-resource actions and scopes are described under Granular Access Control.
| Permission | Description |
|---|---|
ac:read | View custom roles and their permissions |
ac:create | Create new custom roles |
ac:update | Modify custom role permissions |
ac:delete | Delete custom roles |
accessPolicies:read | View access policies for all resource types |
accessPolicies:update | Edit access policies and grant access across all resource types |
agent:read | Open Agents, and use the code sandboxes and files of agents you can use |
agent:create | Create new agents |
agent:delete | Open the trash of deleted agents |
apiKey:read | View API keys |
apiKey:create | Create API keys |
apiKey:delete | Delete API keys |
app:read | Open Apps |
app:create | Create new MCP Apps |
auditLog:read | View audit log records of your own administrative actions |
auditLog:admin | View every audit event in your organization (also requires Read) |
chat:read | View and access chat conversations |
chat:create | Start new chat conversations |
chat:update | Edit chat messages and conversation settings |
chat:delete | Delete chat conversations |
chat:full-view | Show the full chat: the agent picker, model and API key selectors, and expandable tool calls. Without it, chat shows a simpler view |
credential:read | View saved credentials |
credential:create | Create saved credentials |
credential:update | Modify saved credentials |
credential:delete | Delete saved credentials |
environment:read | View and list deployment environments |
environment:create | Create deployment environments |
environment:update | Modify deployment environments, including the org default environment |
environment:delete | Delete deployment environments |
identityProvider:read | View identity provider configurations (SSO) |
identityProvider:create | Set up new identity providers |
identityProvider:update | Modify identity provider settings |
identityProvider:delete | Remove identity providers |
knowledgeSource:read | View Knowledge Bases and Connectors |
knowledgeSource:create | Create Knowledge Bases and Connectors |
knowledgeSource:update | Modify Knowledge Bases and Connectors |
knowledgeSource:delete | Delete Knowledge Bases and Connectors, view the deleted ones, and restore them |
knowledgeSource:query | Query knowledge sources for information retrieval |
llmCost:read | View organization-wide LLM usage cost statistics and analytics |
llmLimit:read | View token usage limits |
llmLimit:create | Create new usage limits |
llmLimit:update | Modify existing usage limits |
llmLimit:delete | Remove usage limits |
llmModel:read | View synced LLM models and capabilities |
llmModel:update | Sync the model catalog and see every model, including ones not shared with you |
llmOauthClient:read | Open LLM OAuth client registrations |
llmOauthClient:create | Create LLM OAuth client registrations |
llmProviderApiKey:read | Open LLM provider API keys |
llmProviderApiKey:create | Add new LLM provider API keys |
llmProxy:read | View the LLM Proxy and its connection details |
llmProxy:update | Modify LLM Proxy configuration |
llmVirtualKey:read | Open LLM virtual keys |
llmVirtualKey:create | Create LLM virtual keys |
log:read | View your own LLM proxy and MCP tool call logs in the active organization |
log:admin | View every LLM and MCP log in your organization (also requires Read) |
mcpGateway:read | Open MCP Gateways |
mcpGateway:create | Create new MCP gateways |
mcpGateway:delete | Open the trash of deleted MCP gateways |
mcpOauthClient:read | Open MCP OAuth client registrations |
mcpOauthClient:create | Create MCP OAuth client registrations |
mcpRegistry:read | Open the MCP registry and use its built-in servers |
mcpRegistry:create | Add servers to the MCP registry |
mcpServerInstallation:read | View installed MCP servers and their status |
mcpServerInstallation:create | Install MCP servers from the registry |
mcpServerInstallation:update | Modify installed MCP server configuration |
mcpServerInstallation:delete | Uninstall, view deleted, and restore MCP servers within your access |
member:read | View organization members and their roles |
member:create | Add new members to the organization and manage invitations |
member:update | Change member roles and settings |
member:delete | Remove members from the organization |
member:impersonate | Temporarily sign in as another member to see the app with their access (role debugging) |
openappaDiagnostics:read | Read all organization yells and your own consult logs |
openappaDiagnostics:update | Resolve and reopen organization yells |
openappaDiagnostics:admin | Read consult logs across the organization |
openappaPolicy:read | View OpenAPPA policy, batteries, and coverage |
openappaPolicy:update | Validate and edit OpenAPPA policy and manage batteries |
organizationSettings:read | View every organization settings page, including messaging channels |
organizationSettings:update | Change organization settings, messaging channels, and site notifications |
plugin:read | View plugins and their file metadata |
plugin:create | Create plugins |
plugin:update | Modify plugin metadata and files |
plugin:delete | Delete plugins |
project:read | View projects and your own sessions inside them |
project:create | Create projects |
project:update | Edit project descriptions, instructions, and sharing |
project:delete | Delete projects |
scheduledTask:read | View scheduled tasks and their run history |
scheduledTask:create | Create new scheduled tasks and trigger runs |
scheduledTask:update | Modify scheduled task configuration |
scheduledTask:delete | Delete scheduled tasks |
serviceAccount:read | Open Service Accounts |
serviceAccount:create | Create service accounts |
skill:read | Open Skills |
skill:create | Create new agent skills |
skill:delete | Permanently delete skills from the trash |
team:read | View teams and their members |
team:create | Create new teams |
team:update | Modify team settings |
team:delete | Delete teams |
toolPolicy:read | View tools, tool invocation policies, and trusted data policies |
toolPolicy:create | Register tools and create security policies |
toolPolicy:update | Modify tools, tool configuration, and security policies |
toolPolicy:delete | Remove tools and security policies |
LLM API Permissions
| API data | Required permissions | Visibility |
|---|---|---|
| View LLM Proxy configuration | llmProxy:read | The active organization's proxy and connection details |
| Update LLM Proxy configuration | llmProxy:update | The active organization's proxy configuration |
Personal usage (/api/statistics/me*) | None | The caller's usage |
| Cost totals, teams, agents, models, and savings | llmCost:read | All matching usage in the active organization |
User cost statistics (/api/statistics/users) | llmCost:read | The caller's usage |
| User cost statistics for all users | llmCost:read and member:read | Identified users in the active organization |
| App cost statistics | llmCost:read and app:read | Apps allowed by the caller’s read grants |
| Skill cost statistics | llmCost:read and skill:read | Skills allowed by the caller’s read grants |
| LLM and MCP logs for the caller | log:read | Records attributed to the caller |
| All LLM and MCP logs | log:read and log:admin | All records in the active organization, including unattributed traffic |
Service accounts use their assigned role for these APIs. A service account has no personal usage or caller-attributed log rows. Grant llmCost:read for organization-wide cost exports. Grant both log:read and log:admin for organization-wide log exports. Add member:read to include per-user cost statistics.