Skip to main content

Who can do what

Delegate has two organization roles and, cutting across them, per-agent access. Most confusion comes from mixing the two up, so it's worth ten minutes now.

Two roles in the organization​

Your role is set per organization. If you belong to more than one, you might be an Admin in one and a User in another.

UserAdmin
Create, configure, and run their own agents✅✅
Use tools and skills✅✅
Create skills✅✅
Manage their own profile, preferences, and API keys✅✅
Open the Organization area—✅
Add and remove members, set roles—✅
Connect integrations (GitHub, Slack, …) and register custom tools—✅
Choose which models are available—✅
Set budgets and view usage & spend—✅
Manage the subscription—✅
Govern skills across the organization—✅
Open any agent in the organization—✅

Users get work done with agents; Admins also run the organization.

Per-agent access​

Separately, each agent has an owner — normally whoever created it — who can share it with colleagues as a Viewer or an Editor.

OwnerViewerEditor
Chat with it, read its history and files✅✅✅
Change its instructions, model, tools, and skills✅—✅
See its memories and scheduled routines✅—✅
Share it with someone else✅——
Delete it✅——

Two things surprise people:

  • An Editor can reconfigure an agent but cannot share it. Widening access stays with the owner.
  • A Viewer can't see memories or routines. Those are configuration, not conversation.

How the two combine​

An Admin can open and configure every agent in the organization, regardless of sharing. There's no way to keep an agent private from an admin — worth knowing before you put something sensitive in one.

The one exception runs the other way: managing an agent's shared users is restricted to its owner, admins included. An admin who needs to change who can reach an agent has to transfer it to themselves first.

Everyone else sees only agents they own or that were shared with them.

Ownership can move: Transfer Ownership hands an agent to someone else, which is how you handle a departure or a change of responsibility. See Sharing an agent.

Where each role goes​

You want to…Go toNeed
Configure an agentAgent → SettingsOwner or Editor
Share an agentAgent → Settings → SharingOwner
Put an agent on your websiteAgent → Settings → Share LinksAdmin
Add a colleague to the organizationOrganization → UsersAdmin
Set spending limitsOrganization → BudgetAdmin
See what everything costOrganization → Usage & SpendAdmin
Connect GitHub or SlackOrganization → IntegrationsAdmin
Change your timezone or sign outUser SettingsAnyone

The exhaustive version​

Permissions reference lists every action in the product with its required role. It's generated from the running application, so it's the authoritative answer when this page and the product seem to disagree.

What about Delegate's own staff?​

Platform support staff can enter your organization to troubleshoot, and you can switch that off. See Support access & auditing for what they can see, what's logged, and how to disable it.