Roles
Every workspace user has one of four roles. Roles determine what a user can manage, not just use:| Role | Who it’s for |
|---|---|
| Admin | Full control — team and user management, gateway settings, all admin functions |
| Org admin | Manages invites, SCIM tokens, and views org-level analytics and billing |
| Editor | Creates and manages agents, knowledge bases, document sets, and prompts — but cannot manage team settings or users |
| Member | Standard user; accesses workspace features according to their group permissions |
Groups and feature permissions
Groups are how you control which features your users can access. Every feature gate in the workspace is controlled by group membership — a user gets a feature if any of their groups has it enabled. Admins manage groups in Admin UI → Groups. Each group has a name and a set of feature permissions you toggle on or off:| Permission | What it unlocks |
|---|---|
voice | Push-to-talk, read-aloud, and voice loop in chat |
web_search | Web search grounding in chat |
image_generation | Image generation in chat |
notes | Markdown notes |
channels | Team channels |
User approval
If your admin has enabled approval-required registration, new accounts start in a pending state and cannot access the workspace until approved. Admins review and approve pending users from Admin UI → Users → Pending. Once approved, the user can sign in and access all features their groups grant them.Access control lists (ACLs)
Notes and document sets use access control lists to restrict visibility. When you share a note or a document set, you choose who can access it using one or more principals:| Principal format | Example | Who gets access |
|---|---|---|
| User ID | usr_abc123 | A specific user |
alice@example.com | A specific user | |
| Internal group | group:<id> | All members of a group |
| External group | extgroup:confluence:engineers | Members synced from an external IdP |
External group sync
If you use Confluence, SharePoint, Slack, or Google Drive connectors, you can sync your IdP’s group memberships directly into ManyLayers:Wait for sync
Groups sync automatically every 30 minutes. After the first sync, the groups appear as
extgroup: principals you can use in ACLs.Personal Access Tokens (PATs)
If you need programmatic access to the workspace — for scripts, integrations, or API exploration — generate a Personal Access Token from Profile → API Key. Your PAT starts withml_pat_ and authenticates as you, with the same permissions as your account. You can revoke it from the same page at any time.