Skip to main content

Permissions

Polygent authorization combines role permissions (what a user can do), workspace membership (where they can do it), ownership rules, and an administrator bypass.

Access model​

A permission answers what a user can do; workspace membership answers where.

For workspace-scoped data, a non-administrator needs both the relevant permission and membership in the workspace. Ownership-sensitive features distinguish the user's own records (sessions, automations, plans) from everyone's. The UI hides unavailable actions, but the server is authoritative and rejects unauthorized requests.

ControlEffect
Role permissionsGrant capabilities; permissions from multiple assigned roles are combined.
Workspace membershipLimits visible and actionable workspace data.
Own versus all permissionsLimits access to records the user owns unless broader access is granted.
AdministratorBypasses permission and workspace checks. Round tables remain private to their creator even for administrators.

The first user to sign in becomes an administrator. Protect that account, assign at least one additional trusted administrator, and use non-administrator accounts for routine work. The last active administrator cannot be blocked, deleted, or demoted.

Permission reference​

This is the complete permission list as shown in the role editor, grouped by category.

CategoryPermissionGrants
AdminAdministratorFull access; bypasses all other checks.
UsersView UsersView users and roles.
Manage UsersCreate, edit, block, and delete users; manage roles; Settings → Active Sessions.
SessionsView Own SessionsView sessions the user owns.
View All SessionsView every session in the user's workspaces.
Create SessionsCreate sessions.
Allow to create new Chat sessionStart Chat sessions.
Allow to create new Develop sessionStart Develop sessions.
Edit SessionsEdit session details and settings.
Delete SessionsDelete sessions.
Manage All SessionsAct on other users' sessions.
Merge to StarterMerge a session branch into its starting branch.
WorkspacesView WorkspacesView workspaces the user belongs to.
Create WorkspacesCreate workspaces.
Edit WorkspacesEdit workspace settings, including budgets, capability ceiling, ticket configuration, and deploy templates.
Delete WorkspacesDelete workspaces.
Manage Workspace UsersAdd and remove workspace members.
HostsView HostsView hosts, slots, and deployments.
Manage HostsApprove and configure hosts; manage slots and run deployments; Hosts settings.
Manage Host API KeysCreate, rotate, revoke, and delete worker credentials.
WorkflowsView Workflows / Manage WorkflowsView, or create, edit, and delete workflows.
SettingsView Settings / Manage SettingsView, or change, application settings, models and backends, Bash policy, branding, and license.
PolygentCodeManage PolygentCode User SettingsChange the harness User Settings.
BotsView Bots / Manage BotsView, or create, edit, and delete bots and categories.
SubagentsView Subagents / Manage SubagentsView, or manage, subagents.
SkillsView Skills / Manage SkillsView, or manage, skills.
InsightsView Insights / Manage InsightsView, or dismiss, regenerate, and link, insights.
AutomationsView Own Automations / View All AutomationsView the user's own, or all, automations.
Manage Automations / Manage All AutomationsCreate and manage the user's own, or any, automations.
PlannerCreate PlansStart plans.
View All PlansOpen other users' plans read-only.
Manage PlansView, edit, and cancel other users' plans.
StatisticsView StatisticsOpen the Statistics dashboard.
Merge ConflictsView Merge Conflicts / Manage Merge ConflictsView, or resolve, retry, and cancel, merge requests.
TicketsView TicketsView tickets.
Manage TicketsCreate, edit, queue, cancel, and delete tickets; retry failed Plans.
Approve DeveloperPerform Developer Approval and approve Plans.
Approve QAPerform QA Approval.
Merge to Starter (Tickets)Skip to Merge: bypass approvals and deliver a ticket directly.
MemoryView Memory / Manage MemoryView, or manage, memory stores and items.
RoundTablesNew Round TableCreate round tables.
Manage PersonasManage personas and enable them per workspace.
MCPsView MCP Servers / Manage MCP ServersView, or manage and connect, external MCP servers.

Two permissions are labeled Merge to Starter: the one under Sessions merges a session branch; the one under Tickets is the Skip to Merge action. Some capabilities also depend on license features and the state of the target record — a permission grants eligibility; it does not override a disabled feature, an invalid state transition, repository protection, or external-provider access.

Manage roles​

Roles are reusable permission bundles managed with the users.

  1. Open Settings → Users → Roles with Manage Users.
  2. Create a role with a purpose-specific name.
  3. Select only the permissions required for that job function.
  4. Assign one or more roles to each user on the Users tab.
  5. Add non-administrators to the workspaces they need.
  6. Test with a non-administrator account before broad rollout.

A role cannot be deleted while assigned to users, and the built-in Admin role cannot be deleted. Role changes apply to every assigned user, so review membership before expanding a shared role.

Promoting a user to administrator removes their explicit workspace memberships (administrators see every workspace). Demoting an administrator adds them to every workspace — remove the memberships they should not keep immediately afterward.

Manage workspace membership​

Workspace membership is the tenant boundary for non-administrators.

Open the workspace's Users tab (visible with Manage Workspace Users) and add or remove users. A new workspace has no members; its creator must be added unless they are an administrator. Removing membership hides the workspace's resources but does not delete the user's account, roles, authored records, or history.

Administrators see every workspace without membership. Do not grant Administrator to solve a missing-membership issue; add the user to the workspace instead.

Start with narrow roles and add capabilities only when a verified workflow requires them.

RoleRecommended permissions
SupporterView Users, View Workspaces, View All Sessions, View Tickets, View Hosts, View Statistics, View Insights, View Merge Conflicts, View Settings.
DeveloperCreate Sessions, Allow to create new Chat/Develop session, View Own Sessions, Edit Sessions, View Tickets, Approve Developer, Merge to Starter (Sessions).
QA reviewerView All Sessions, View Tickets, Approve QA, View Statistics.
Deployment operatorView Hosts, Manage Hosts; add Manage Host API Keys only when credential rotation is part of the role. Edit Workspaces is needed to change deploy templates.
Security administratorManage Users, Manage Settings, Manage Host API Keys; avoid routine development permissions where separation of duties is required.
Read-only stakeholderView-only permissions for the required modules, plus workspace membership.

The matrix has no wildcard permissions. Review new permissions after every upgrade; existing custom roles do not automatically include newly added capabilities.

Security operations​

Authorization changes are security-sensitive configuration.

  • Keep Administrator, Manage Users, Manage Settings, Manage Host API Keys, Merge to Starter (Tickets), and Manage Hosts narrowly assigned.
  • Separate credential management from day-to-day worker or slot operation where possible.
  • During offboarding, block the user (this also frees their license seat), then remove roles and workspace memberships. Users who own records cannot be deleted; blocking preserves history.
  • Revoke devices and external personal access tokens separately; role removal alone does not revoke every credential.
  • Periodically review role membership against current job responsibilities.
  • Test denial as well as success: confirm a user cannot see unrelated workspaces or perform destructive actions.

Troubleshooting​

Resolve access problems by checking permission, membership, ownership, license, and target state, in that order.

SymptomResolution
Workspace is missingAdd the non-administrator user on the workspace Users tab.
Creator cannot see a new workspaceWorkspaces start without members; add the creator.
Action is hidden or access is deniedGrant the exact permission through an assigned role and confirm workspace membership.
User can view only some sessionsGrant View All Sessions if justified; View Own Sessions intentionally limits scope.
User cannot manage another user's automation or sessionGrant Manage All Automations or Manage All Sessions rather than Administrator.
Role cannot be deletedRemove it from all users; the built-in Admin role cannot be deleted.
User cannot be deletedThe user owns records; block the user instead.
Former administrator has access to every workspaceDemotion adds all memberships; remove the unwanted ones.
Permission appears correct but feature is absentCheck the installed license and whether the feature is enabled and configured.
Administrator cannot open a round tableExpected; round tables are private to their creator.
User retained an external capability after offboardingRevoke identity-provider sessions, personal access tokens, host keys, and repository/provider credentials separately.