Roles

Every workspace user has one of four roles. Roles determine what a user can manage, not just use:
RoleWho it’s for
AdminFull control — team and user management, gateway settings, all admin functions
Org adminManages invites, SCIM tokens, and views org-level analytics and billing
EditorCreates and manages agents, knowledge bases, document sets, and prompts — but cannot manage team settings or users
MemberStandard user; accesses workspace features according to their group permissions

Groups and feature permissions

Groups are how you control which features your users can access. Every feature gate in the workspace is controlled by group membership — a user gets a feature if any of their groups has it enabled. Admins manage groups in Admin UI → Groups. Each group has a name and a set of feature permissions you toggle on or off:
PermissionWhat it unlocks
voicePush-to-talk, read-aloud, and voice loop in chat
web_searchWeb search grounding in chat
image_generationImage generation in chat
notesMarkdown notes
channelsTeam channels
To give a user a feature, add them to a group that has the permission enabled. Users can check their own group memberships and effective permissions from Profile → Groups.

User approval

If your admin has enabled approval-required registration, new accounts start in a pending state and cannot access the workspace until approved. Admins review and approve pending users from Admin UI → Users → Pending. Once approved, the user can sign in and access all features their groups grant them.

Access control lists (ACLs)

Notes and document sets use access control lists to restrict visibility. When you share a note or a document set, you choose who can access it using one or more principals:
Principal formatExampleWho gets access
User IDusr_abc123A specific user
Emailalice@example.comA specific user
Internal groupgroup:<id>All members of a group
External groupextgroup:confluence:engineersMembers synced from an external IdP
An empty ACL means the resource is private — only the owner can see it.

External group sync

If you use Confluence, SharePoint, Slack, or Google Drive connectors, you can sync your IdP’s group memberships directly into ManyLayers:
1

Enable group sync on a connector

Open the connector’s settings and turn on Sync Groups.
2

Wait for sync

Groups sync automatically every 30 minutes. After the first sync, the groups appear as extgroup: principals you can use in ACLs.
3

Use in ACLs

When sharing a note or document set, type the external group name (for example, extgroup:confluence:engineers) to grant access to everyone in that group. Access stays in sync as IdP group membership changes.
If the external group lookup fails, access falls back to email-only matching.

Personal Access Tokens (PATs)

If you need programmatic access to the workspace — for scripts, integrations, or API exploration — generate a Personal Access Token from Profile → API Key. Your PAT starts with ml_pat_ and authenticates as you, with the same permissions as your account. You can revoke it from the same page at any time.