Skip to main content

Permissions reference

Every action Delegate exposes, and who is allowed to take it. This page is generated from the running application — each entry reflects the check the server actually performs, not a description of it — so it cannot drift from the product without failing the build.

For the short version in prose, see Who can do what.

How to read it​

WhoMeans
Anyone (no sign-in)No account needed.
Any signed-in userAny Delegate account, acting on its own profile or credentials.
Any memberAny member of the organization, User or Admin.
Anyone the agent is shared withThe owner, an Admin, or someone it was shared with as Viewer or Editor.
Agent owner or EditorThe owner, an Admin, or someone it was shared with as Editor.
Agent ownerOnly the person who owns the agent.
AdminsAdmins of the organization.

Admins can open and configure every agent in their organization, so where a row names an agent role, an Admin generally qualifies too. Sharing is the exception: rows marked Agent owner mean the owner alone, and an admin who does not own the agent cannot manage who it is shared with.

Platform-operations actions are not listed: they are not available to any customer account.

Agents​

ActionWho can do it
Clone an agentAnyone the agent is shared with
Create new agentAny member
Delete agentAgent owner or Admins
Export an agent as a portable bundleAgent owner or Admins
Get agent by IDAnyone the agent is shared with
Get user's agentsAny member
Reset agent bootstrapAgent owner or Editor
Transfer agent ownershipAgent owner or Admins
Update agentAdmins

Agent configuration​

ActionWho can do it
Add bundle to agentAgent owner or Editor
Add tool to agentAgent owner or Editor
Get agent's bundlesAnyone the agent is shared with
Get agent's toolsAnyone the agent is shared with
Get all available toolsAny member
Get all tool bundlesAny member
Get available bundles for tenantAny member
Get tool by IDAny member
Re-read a registered MCP server's tool catalogueAgent owner or Editor
Remove bundle from agentAgent owner or Editor
Remove tool from agentAgent owner or Editor
Set an agent's credentials for a toolAgent owner or Editor
Update agent tool configurationAgent owner or Editor
Update bundle configurationAgent owner or Editor

Agent content​

ActionWho can do it
Create a scheduled routine for an agentAgent owner or Editor
Delete a file from an agent's workspaceAgent owner or Editor
Delete a memoryAgent owner or Editor
Delete a scheduled routineAgent owner or Editor
Download an agent fileAnyone the agent is shared with
List an agent's files in a zoneAnyone the agent is shared with
List memories for an agentAgent owner or Editor
List scheduled routines for an agentAgent owner or Editor
Update a memory's type and/or contentAgent owner or Editor
Update a scheduled routineAgent owner or Editor
Upload a file to an agent's workspaceAgent owner or Editor

Sharing​

ActionWho can do it
Create a share link for an agentAdmins
List share links for an agentAdmins
List shared users for an agentAgent owner
Remove shared user from agentAgent owner
Revoke a share linkAdmins
Share agent with a userAgent owner
Update a share link's embed allow-list or upload policyAdmins
Update shared user's roleAgent owner

Conversations​

ActionWho can do it
Cancel a running taskAny member
Create or update message feedbackAnyone the agent is shared with
Delete a task sessionAnyone the agent is shared with
Execute a task using AI orchestration (streaming)Anyone the agent is shared with
Get a task session with messagesAnyone the agent is shared with
Get debug information for a task session (admin only)Admins
List task sessions for an agentAnyone the agent is shared with
Poll for new events on an in-progress task sessionAnyone the agent is shared with
Remove message feedbackAnyone the agent is shared with
Resume a running task's event streamAny member
Search an agent's task sessions (semantic + fuzzy)Anyone the agent is shared with
Store a credential in encrypted skill configurationAgent owner or Editor
Upsert message feedbackAnyone the agent is shared with

Skills​

ActionWho can do it
Attach skill to agentAgent owner or Editor
Create a skillAny member
Detach skill from agentAgent owner or Editor
Download binary file from skillAny member
Get skill with filesAny member
List agent's skillsAgent owner or Editor
List public active skills (no auth)Anyone (no sign-in) (public)
List skills visible to tenantAny member
Update a skillAny member
Upload binary file to skillAny member

Custom tools​

ActionWho can do it
Delete a custom toolAdmins
List this tenant's custom toolsAdmins
Read a tenant's egress allow-listAdmins
Register a custom toolAdmins
Set a tenant's egress allow-listAdmins
Update a custom toolAdmins

Connections​

ActionWho can do it
Complete GitHub connection flowAdmins
Complete Google Workspace Admin connection flowAdmins
Complete Slack connection flowAdmins
Complete Slack user OAuth flow for an agentAgent owner or Editor
Connect DocWorkerAdmins
Disconnect Slack user from an agentAgent owner or Editor
Disconnect tenant connectionAdmins
Get tenant connection detailsAdmins
List tenant connectionsAdmins
Start GitHub connection flowAdmins
Start Google Workspace Admin connection flowAdmins
Start Slack connection flowAdmins
Start Slack user OAuth flow for an agentAgent owner or Editor

Organization administration​

ActionWho can do it
Add an allowed accountAdmins
Bulk toggle tenant model accessAdmins
Bulk update agent-skill assignmentsAdmins
Bulk-update per-agent budget allocationsAdmins
Bulk-update per-user budget allocationsAdmins
Change agent owner within tenantAdmins, or admins of the agent's group
Create or attach a user in a tenantAdmins
Delete a skillAdmins
Delete a tenant's BYOK key for a providerAdmins
Edit a user's name and emailAdmins
Export a skill as Agent Skills spec zipAdmins
Get allowed accounts for a tenantAdmins
Get per-agent LLM cost breakdownAdmins
Get per-user LLM cost breakdownAdmins
Get tenant budget configuration and current usageAdmins
Get tenant default bootstrap instructionsAdmins
Get tenant default skill visibility scopeAdmins
Get tenant superadmin-impersonation policyAdmins
List a tenant's BYOK LLM credentialsAdmins
List agents attached to a skillAdmins
List agents with their attached skillsAdmins
List all skills in a tenantAdmins
List budget enforcement events for a tenantAdmins
List models with tenant access statusAdmins
List per-agent budget allocations + live usageAdmins
List per-user budget allocations + live usageAdmins
Remove admin privileges from a userAdmins
Remove an allowed accountAdmins
Retrieve users by tenant IDAdmins
Set agent skill visibility scopeAdmins
Set or replace a tenant's BYOK key for a providerAdmins
Set tenant default skill visibility scopeAdmins
Set tenant superadmin-impersonation policyAdmins
Soft delete a userAdmins
Toggle agent skill authoring permissionAdmins
Update skill statusAdmins
Update tenant budget configurationAdmins
Update tenant default bootstrap instructionsAdmins
Update tenant model accessAdmins

Groups​

ActionWho can do it
Add a member to a groupGroup admins or Admins
Change a member's group roleGroup admins or Admins
Create a groupAdmins
Delete a groupAdmins
Get a groupGroup members or Admins
List group membersGroup members or Admins
List my groupsAny member
Remove a member from a groupGroup admins or Admins
Rename or describe a groupAdmins

Billing & budgets​

ActionWho can do it
Attach payment method and (re)subscribeAdmins
Cancel the tenant subscriptionAdmins
Create a Stripe SetupIntent for the tenantAdmins
List the tenant's recent Stripe invoicesAdmins
Reconcile billing reports vs. live TaskUsage sumsAdmins
Record admin acknowledgement of subscription terms and disclosuresAdmins
Tenant billing statusAdmins

Models​

ActionWho can do it
Get model detailsAny member
List available modelsAny member

Identity & preferences​

ActionWho can do it
Create or update voice config for the current user on an agentAnyone the agent is shared with
Delete a voice configAnyone the agent is shared with
Favorite an agentAny member
Get company identityAny member
Get current user's identityAny member
Get mentionable entities for autocompleteAny member
Get user's favorite agentsAny member
List voice configs for the current user on an agentAnyone the agent is shared with
Record agent accessAny member
Unfavorite an agentAny member
Update a voice configAnyone the agent is shared with
Update company identityAdmins
Update current user's identityAny member

API keys​

ActionWho can do it
Create a user API keyAny signed-in user
List user API keysAny signed-in user
List user's API keys (admin)Admins
Mint an API key for a user (admin)Admins
Revoke a user API keyAny signed-in user
Revoke a user's API key (admin)Admins
Revoke all of a user's API keys (admin)Admins

Public surfaces​

ActionWho can do it
Chat with a shared agent (streaming, read-only toolset)Anyone (no sign-in) (public)
Drop-in embed loader scriptAnyone (no sign-in) (public)
Fetch a visitor's persisted session messagesAnyone (no sign-in) (public)
Framable chat document for a share linkAnyone (no sign-in) (public)
Read a documentation page by slugAnyone (no sign-in) (public)
Resolve a share link to limited agent infoAnyone (no sign-in) (public)
Resume a running shared task's event streamAnyone (no sign-in) (public)
Search public documentationAnyone (no sign-in) (public)

What isn't here​

Platform-operations capabilities — managing tenants, the global model registry and its pricing, self-hosted endpoints, and cross-organization skill publishing — are held by Delegate's own staff and are not part of any customer role. What support staff can see in your organization, and how to switch it off, is covered in Support access & auditing.