Configuration
Roles
Nested workspace roles for access control and approval gating.
Roles are custom workspace identities used for permission matrices and human-in-the-loop approvals. You can nest roles up to three levels (L1–L3). They are separate from membership flags such as Owner and Developer, which control who can manage the workspace and see Dev-only menus.
Use them when tables, widgets, in-app channels, or agent tools should be limited to specific groups of members.
When to use
- Restrict table or column access by role
- Nest org roles (parent → child) for inheritance-friendly permission setup
- Gate agent tools with Require role approval
Create a role
Open Configuration → Workspace Settings → Roles.
- Choose Create Role, or add a child with + on a role that is below level 3.
- Set Name (max 100 characters), optional Description, and optional Parent Role.
- Save. Parent cannot change after create.
| Setting | What it does |
|---|---|
| Name | Unique label in the workspace |
| Description | Optional notes |
| Parent Role | Empty for a root (L1) role; otherwise nests under a parent (max depth 3) |
Owners can open Users on a role to assign or remove workspace members. Viewing and assigning users on roles is Owner-only; Developers can manage role definitions depending on settings access.
How roles differ from Owner / Developer
| Concept | Purpose |
|---|---|
| Owner / Developer | Account membership on the workspace — admin surfaces, Dev-gated sidebar items |
| Custom roles | Resource permissions (tables, fields, widgets, in-app View) and approval assignees |
A person can be a Developer and also hold one or more custom roles.
Where roles apply
| Place | How |
|---|---|
| Tables / columns | Role permission grids for read/write access |
| Widgets / In App chat | Role-based access (View on in-app chat integrations) |
| Agent tools | Require role approval — members with those roles approve on Approvals (or in-chat when they are the current user). See Approval flow. |
| Request Information | Collect answers from role holders before a run continues |
Limits
- Maximum nesting depth is 3 levels.
- Role names must be unique in the workspace.
- Parent is locked after create; create a new role if you need a different parent.
Where roles are used
| Place | How |
|---|---|
| Tables, widgets, in-app chat | Access matrices |
| Approvals | Role-based tool and step gating — see Approval flow |