Skip to main content

AI and Agent Permissions

Configure AI and Agent Permissions through global user roles to control feature access, agent creation, sharing, and read, use, and manage levels

AI permissions are part of global user roles. They determine which features a user is allowed to use in the AI area.

With agents, there's an additional distinction between agent access and access to context. To run an agent in a task or project, you need both permissions.

Important: An agent is not a user. It doesn't have its own awork role and doesn't have its own permissions. Every run is executed on behalf of a responsible user.


What AI permissions are available?

No Access

Users with no access cannot use AI and agents.

They can still be part of the AI subscription. The setting affects access, not billing.

Use AI & Agents - without Sharing

This is the default setting.

Users can:

  • Use AI
  • Use agents
  • Create their own agents
  • Create their own skills

Your own agents and skills cannot be shared with the Workspace Library.

Use AI & Agents - Share in Library

In addition to the default settings, users can share agents and skills with the Workspace Library.


Access rights for agents

For agents, there are the following permissions: None, Read and use, and Manage.

None

Users cannot find, open, configure, or run the agent.

Historical agent activity and context-related threads may still be visible if the user has read access to the respective task or project context.

Read and Use

With read and use, the user can:

  • Open the agent and view details
  • Run agents if you also have write access to the specific task or project context
  • Use linked skills, including private agent skills
  • Use linked connectors, provided the responsible user's connection is available

Read permissions do not allow changes to the agent configuration.

Manage

Manage includes all read permissions and additionally allows you to edit the agent and change its settings or sharing.

This includes configuration, versions, avatar, sharing, memory, skills, connectors, workflows, schedules, and archive status.


How are agent permissions assigned?

An agent can be shared with the entire workspace, teams, or individual users.

  • Creator and workspace administrators: Always have permission to manage the agent
  • Multiple sharing: The highest permission applies
  • New agents: Are initially only accessible to the creator and workspace administrators
  • No additional permission: Read access allows you to use the agent

What permission do I need?

ActionRequired Permission
Create agentAuthorized internal workspace user with agent access
Open agentAgent read and use
Edit or share agentAgent manage
Start standalone threadAgent read and use
Run agent in task or projectAgent read and use + write access to the specific context
Mention agent in commentAgent read and use + write access to the commented context
Read existing task/project threadRead access to the specific context
Continue task/project threadAgent read and use + write access to the specific context
Cancel context-related runWrite access to the specific context
Cancel standalone runCreator only
See agent activity and run historyRead access to the task/project context
Create, edit, delete, or manually start scheduleAgent manage + required access to the selected context

AI thread permissions at project level and agent activity

For projects, there's an additional permission for AI Threads.

It determines whether users are allowed to see AI threads that are connected to a project.

There are two levels:

  • Read access
  • No access

There is no separate edit permission for AI threads.

Standalone threads are private to their creator. Even workspace administrators don't get access to other people's standalone threads this way.

Agent Activity shows agent involvement in tasks and projects. It doesn't grant any permissions itself and doesn't make an agent a task member or project member.

When a thread is deleted, involvement and run history are retained. A later run creates a new thread if no available thread exists anymore.


Adjust permission levels for AI and agents

Admin permissions are required.

  1. Open Settings (gear icon in the bottom left of the main menu).

  2. Navigate to the Admin category and select Rights Management.

  3. Open the General Permission Role

  4. Scroll to the AI Permissions section. There you'll find the permission for awork Agent & Custom Agents with a dropdown selection field on the right side of the row.

  5. Open the permissions dropdown
    Click on the dropdown field next to awork Agent & Custom Agents. The field shows the currently selected permission level and contains a small arrow icon that indicates additional options.

  6. Select permission level
    In the opened dropdown menu with the heading Permission Level, you have three options:

    • No Access: Users have no access to AI features and cannot use awork Agent or custom agents.
    • Use AI & Agents - without Sharing: Users can use awork Agent and custom agents but cannot share them with others.
    • Use AI & Agents - Share in Library: Users can use awork Agent and custom agents and additionally share them in the Library with others.
    Step 4
  7. Select your preferred option
    Click on the permission level you want to set for users. The selected option is applied immediately and displayed in the dropdown field.

AI permissions are now configured for the user role. The changes apply immediately to all users with this role.


Who is the responsible user?

Every agent run has a responsible user. Their awork permissions, personal skills, and personal connector connections are used for the run.

  • Direct run or follow-up: The user who selects run agent or sends the message is responsible.
  • Agent mention in comment: The user who adds the agent mention is responsible.
  • Automatic schedule: The responsible user of the schedule remains responsible.
  • Run schedule now: The schedule owner remains responsible. The user who selects run now is additionally recorded as the triggering user.
  • Delegated or sub-agent run: The run adopts the responsible and triggering user of the parent run.

When a user saves or edits a schedule, they become responsible for future runs.

Important: If the required permissions are missing, the user is inactive, or the permission cannot be verified, the run is rejected or stops at the next protected boundary.


Permissions during an agent run

Permissions are checked when the run is accepted.

Important: Existing sharing and approval rules continue to apply. Agents do not bypass any permissions or approvals.

All users who have access to a task or project can start an agent run there.

The agent always works with the permissions of the user who starts it. This means: If you don't have permission to edit a task or project, the agent also cannot make changes there. In this case, the agent is limited to read access.

Even without edit rights, an agent run can be useful, for example for a health check, a summary, or a quick translation.

In short: If you can read a task or project, you can also start an agent run for it. Changes are only possible if you have the corresponding edit rights.


FAQ

Is agent read permission enough to start an agent in a task?

No. You also need write access to the specific task or project context.

Does an agent have its own awork permissions?

No. An agent doesn't have its own awork role. Every run uses the permissions of the responsible human user.

Can workspace administrators read other people's standalone threads?

No. Admin rights do not override the privacy of a standalone thread.

What happens if the responsible user no longer has permission?

The run is rejected or stops at the next protected boundary.

Last updated HappySupportPowered by happysupport.ai
© 2026 HappySupport. All rights reserved.
HappySearch can make mistakes.

Sources

No articles yet

Search to see source articles