Who can do what
Delegate has two organization roles and, cutting across them, per-agent access. Most confusion comes from mixing the two up, so it's worth ten minutes now.
Two roles in the organization
Your role is set per organization. If you belong to more than one, you might be an Admin in one and a User in another.
| User | Admin | |
|---|---|---|
| Create, configure, and run their own agents | ✅ | ✅ |
| Use tools and skills | ✅ | ✅ |
| Create skills | ✅ | ✅ |
| Manage their own profile, preferences, and API keys | ✅ | ✅ |
| Open the Organization area | — | ✅ |
| Add and remove members, set roles | — | ✅ |
| Connect integrations (GitHub, Slack, …) and register custom tools | — | ✅ |
| Choose which models are available | — | ✅ |
| Set budgets and view usage & spend | — | ✅ |
| Manage the subscription | — | ✅ |
| Govern skills across the organization | — | ✅ |
| Open any agent in the organization | — | ✅ |
Users get work done with agents; Admins also run the organization.
Per-agent access
Separately, each agent has an owner — normally whoever created it — who can share it with colleagues as a Viewer or an Editor.
| Owner | Viewer | Editor | |
|---|---|---|---|
| Chat with it, read its history and files | ✅ | ✅ | ✅ |
| Change its instructions, model, tools, and skills | ✅ | — | ✅ |
| See its memories and scheduled routines | ✅ | — | ✅ |
| Share it with someone else | ✅ | — | — |
| Delete it | ✅ | — | — |
Two things surprise people:
- An Editor can reconfigure an agent but cannot share it. Widening access stays with the owner.
- A Viewer can't see memories or routines. Those are configuration, not conversation.
How the two combine
An Admin can open and configure every agent in the organization, regardless of sharing. There's no way to keep an agent private from an admin — worth knowing before you put something sensitive in one.
The one exception runs the other way: managing an agent's shared users is restricted to its owner, admins included. An admin who needs to change who can reach an agent has to transfer it to themselves first.
Everyone else sees only agents they own or that were shared with them.
Ownership can move: Transfer Ownership hands an agent to someone else, which is how you handle a departure or a change of responsibility. See Sharing an agent.
Where each role goes
| You want to… | Go to | Need |
|---|---|---|
| Configure an agent | Agent → Settings | Owner or Editor |
| Share an agent | Agent → Settings → Sharing | Owner |
| Put an agent on your website | Agent → Settings → Share Links | Admin |
| Add a colleague to the organization | Organization → Users | Admin |
| Set spending limits | Organization → Budget | Admin |
| See what everything cost | Organization → Usage & Spend | Admin |
| Connect GitHub or Slack | Organization → Integrations | Admin |
| Change your timezone or sign out | User Settings | Anyone |
The exhaustive version
Permissions reference lists every action in the product with its required role. It's generated from the running application, so it's the authoritative answer when this page and the product seem to disagree.
What about Delegate's own staff?
Platform support staff can enter your organization to troubleshoot, and you can switch that off. See Support access & auditing for what they can see, what's logged, and how to disable it.