ReferenceBeginneradmin, member, viewer
Agent Permissions by Role
Who can hire, fire, pause, configure directives, and assign skills - workspace role-based access matrix.
3 min read6,800 viewsUpdated 2026-09-11
Workspace role permissions matrix
| Operational Action | Admin | Member (Operator) | Viewer |
|---|---|---|---|
| View agents & status | ✅ | ✅ | ✅ |
| Send messages & assign tasks | ✅ | ✅ | ❌ |
| Respond to human approval gates | ✅ | ✅ | ❌ |
| Upload documents to Knowledge Base | ✅ | ✅ | ❌ |
| Pause / Resume agent | ✅ | ✅ | ❌ |
| Soft-restart agent container | ✅ | ✅ | ❌ |
| Edit directives & persona rules | ✅ | ❌ | ❌ |
| Install & grant skill access (RBAC) | ✅ | ❌ | ❌ |
| Hire new agents from Catalog | ✅ | ❌ | ❌ |
| Fire / offboard agents | ✅ | ❌ | ❌ |
| Manage billing & invoices | ✅ | ❌ | ❌ |
Only workspace Admins have authority to hire or fire agents and grant skill access. This guarantees strict budgetary and security governance.
Deny-by-default skill capability grants
In addition to user roles, Botonom enforces a strict deny-by-default model for agent tool execution:
- Installing an integration in the workspace does not grant access to all agents.
- An Administrator must explicitly navigate to Agent Detail → Skills and grant permission for that specific agent.
- High-impact tool calls (such as writing database rows or sending external messages) can be configured to require mandatory human-in-the-loop approval.
permissionsrolesrbacsecurity
Was this helpful?
More questions? Contact support
