Permissions reference
Every action Delegate exposes, and who is allowed to take it. This page is generated from the running application — each entry reflects the check the server actually performs, not a description of it — so it cannot drift from the product without failing the build.
For the short version in prose, see Who can do what.
How to read it
| Who | Means |
|---|---|
| Anyone (no sign-in) | No account needed. |
| Any signed-in user | Any Delegate account, acting on its own profile or credentials. |
| Any member | Any member of the organization, User or Admin. |
| Anyone the agent is shared with | The owner, an Admin, or someone it was shared with as Viewer or Editor. |
| Agent owner or Editor | The owner, an Admin, or someone it was shared with as Editor. |
| Agent owner | Only the person who owns the agent. |
| Admins | Admins of the organization. |
Admins can open and configure every agent in their organization, so where a row names an agent role, an Admin generally qualifies too. Sharing is the exception: rows marked Agent owner mean the owner alone, and an admin who does not own the agent cannot manage who it is shared with.
Platform-operations actions are not listed: they are not available to any customer account.
Agents
| Action | Who can do it |
|---|---|
| Clone an agent | Anyone the agent is shared with |
| Create new agent | Any member |
| Delete agent | Agent owner or Admins |
| Export an agent as a portable bundle | Agent owner or Admins |
| Get agent by ID | Anyone the agent is shared with |
| Get user's agents | Any member |
| Reset agent bootstrap | Agent owner or Editor |
| Transfer agent ownership | Agent owner or Admins |
| Update agent | Admins |
Agent configuration
| Action | Who can do it |
|---|---|
| Add bundle to agent | Agent owner or Editor |
| Add tool to agent | Agent owner or Editor |
| Get agent's bundles | Anyone the agent is shared with |
| Get agent's tools | Anyone the agent is shared with |
| Get all available tools | Any member |
| Get all tool bundles | Any member |
| Get available bundles for tenant | Any member |
| Get tool by ID | Any member |
| Re-read a registered MCP server's tool catalogue | Agent owner or Editor |
| Remove bundle from agent | Agent owner or Editor |
| Remove tool from agent | Agent owner or Editor |
| Set an agent's credentials for a tool | Agent owner or Editor |
| Update agent tool configuration | Agent owner or Editor |
| Update bundle configuration | Agent owner or Editor |
Agent content
| Action | Who can do it |
|---|---|
| Create a scheduled routine for an agent | Agent owner or Editor |
| Delete a file from an agent's workspace | Agent owner or Editor |
| Delete a memory | Agent owner or Editor |
| Delete a scheduled routine | Agent owner or Editor |
| Download an agent file | Anyone the agent is shared with |
| List an agent's files in a zone | Anyone the agent is shared with |
| List memories for an agent | Agent owner or Editor |
| List scheduled routines for an agent | Agent owner or Editor |
| Update a memory's type and/or content | Agent owner or Editor |
| Update a scheduled routine | Agent owner or Editor |
| Upload a file to an agent's workspace | Agent owner or Editor |
Sharing
| Action | Who can do it |
|---|---|
| Create a share link for an agent | Admins |
| List share links for an agent | Admins |
| List shared users for an agent | Agent owner |
| Remove shared user from agent | Agent owner |
| Revoke a share link | Admins |
| Share agent with a user | Agent owner |
| Update a share link's embed allow-list or upload policy | Admins |
| Update shared user's role | Agent owner |
Conversations
| Action | Who can do it |
|---|---|
| Cancel a running task | Any member |
| Create or update message feedback | Anyone the agent is shared with |
| Delete a task session | Anyone the agent is shared with |
| Execute a task using AI orchestration (streaming) | Anyone the agent is shared with |
| Get a task session with messages | Anyone the agent is shared with |
| Get debug information for a task session (admin only) | Admins |
| List task sessions for an agent | Anyone the agent is shared with |
| Poll for new events on an in-progress task session | Anyone the agent is shared with |
| Remove message feedback | Anyone the agent is shared with |
| Resume a running task's event stream | Any member |
| Search an agent's task sessions (semantic + fuzzy) | Anyone the agent is shared with |
| Store a credential in encrypted skill configuration | Agent owner or Editor |
| Upsert message feedback | Anyone the agent is shared with |
Skills
| Action | Who can do it |
|---|---|
| Attach skill to agent | Agent owner or Editor |
| Create a skill | Any member |
| Detach skill from agent | Agent owner or Editor |
| Download binary file from skill | Any member |
| Get skill with files | Any member |
| List agent's skills | Agent owner or Editor |
| List public active skills (no auth) | Anyone (no sign-in) (public) |
| List skills visible to tenant | Any member |
| Update a skill | Any member |
| Upload binary file to skill | Any member |
Custom tools
| Action | Who can do it |
|---|---|
| Delete a custom tool | Admins |
| List this tenant's custom tools | Admins |
| Read a tenant's egress allow-list | Admins |
| Register a custom tool | Admins |
| Set a tenant's egress allow-list | Admins |
| Update a custom tool | Admins |
Connections
| Action | Who can do it |
|---|---|
| Complete GitHub connection flow | Admins |
| Complete Google Workspace Admin connection flow | Admins |
| Complete Slack connection flow | Admins |
| Complete Slack user OAuth flow for an agent | Agent owner or Editor |
| Connect DocWorker | Admins |
| Disconnect Slack user from an agent | Agent owner or Editor |
| Disconnect tenant connection | Admins |
| Get tenant connection details | Admins |
| List tenant connections | Admins |
| Start GitHub connection flow | Admins |
| Start Google Workspace Admin connection flow | Admins |
| Start Slack connection flow | Admins |
| Start Slack user OAuth flow for an agent | Agent owner or Editor |
Organization administration
| Action | Who can do it |
|---|---|
| Add an allowed account | Admins |
| Bulk toggle tenant model access | Admins |
| Bulk update agent-skill assignments | Admins |
| Bulk-update per-agent budget allocations | Admins |
| Bulk-update per-user budget allocations | Admins |
| Change agent owner within tenant | Admins, or admins of the agent's group |
| Create or attach a user in a tenant | Admins |
| Delete a skill | Admins |
| Delete a tenant's BYOK key for a provider | Admins |
| Edit a user's name and email | Admins |
| Export a skill as Agent Skills spec zip | Admins |
| Get allowed accounts for a tenant | Admins |
| Get per-agent LLM cost breakdown | Admins |
| Get per-user LLM cost breakdown | Admins |
| Get tenant budget configuration and current usage | Admins |
| Get tenant default bootstrap instructions | Admins |
| Get tenant default skill visibility scope | Admins |
| Get tenant superadmin-impersonation policy | Admins |
| List a tenant's BYOK LLM credentials | Admins |
| List agents attached to a skill | Admins |
| List agents with their attached skills | Admins |
| List all skills in a tenant | Admins |
| List budget enforcement events for a tenant | Admins |
| List models with tenant access status | Admins |
| List per-agent budget allocations + live usage | Admins |
| List per-user budget allocations + live usage | Admins |
| Remove admin privileges from a user | Admins |
| Remove an allowed account | Admins |
| Retrieve users by tenant ID | Admins |
| Set agent skill visibility scope | Admins |
| Set or replace a tenant's BYOK key for a provider | Admins |
| Set tenant default skill visibility scope | Admins |
| Set tenant superadmin-impersonation policy | Admins |
| Soft delete a user | Admins |
| Toggle agent skill authoring permission | Admins |
| Update skill status | Admins |
| Update tenant budget configuration | Admins |
| Update tenant default bootstrap instructions | Admins |
| Update tenant model access | Admins |
Groups
| Action | Who can do it |
|---|---|
| Add a member to a group | Group admins or Admins |
| Change a member's group role | Group admins or Admins |
| Create a group | Admins |
| Delete a group | Admins |
| Get a group | Group members or Admins |
| List group members | Group members or Admins |
| List my groups | Any member |
| Remove a member from a group | Group admins or Admins |
| Rename or describe a group | Admins |
Billing & budgets
| Action | Who can do it |
|---|---|
| Attach payment method and (re)subscribe | Admins |
| Cancel the tenant subscription | Admins |
| Create a Stripe SetupIntent for the tenant | Admins |
| List the tenant's recent Stripe invoices | Admins |
| Reconcile billing reports vs. live TaskUsage sums | Admins |
| Record admin acknowledgement of subscription terms and disclosures | Admins |
| Tenant billing status | Admins |
Models
| Action | Who can do it |
|---|---|
| Get model details | Any member |
| List available models | Any member |
Identity & preferences
| Action | Who can do it |
|---|---|
| Create or update voice config for the current user on an agent | Anyone the agent is shared with |
| Delete a voice config | Anyone the agent is shared with |
| Favorite an agent | Any member |
| Get company identity | Any member |
| Get current user's identity | Any member |
| Get mentionable entities for autocomplete | Any member |
| Get user's favorite agents | Any member |
| List voice configs for the current user on an agent | Anyone the agent is shared with |
| Record agent access | Any member |
| Unfavorite an agent | Any member |
| Update a voice config | Anyone the agent is shared with |
| Update company identity | Admins |
| Update current user's identity | Any member |
API keys
| Action | Who can do it |
|---|---|
| Create a user API key | Any signed-in user |
| List user API keys | Any signed-in user |
| List user's API keys (admin) | Admins |
| Mint an API key for a user (admin) | Admins |
| Revoke a user API key | Any signed-in user |
| Revoke a user's API key (admin) | Admins |
| Revoke all of a user's API keys (admin) | Admins |
Public surfaces
| Action | Who can do it |
|---|---|
| Chat with a shared agent (streaming, read-only toolset) | Anyone (no sign-in) (public) |
| Drop-in embed loader script | Anyone (no sign-in) (public) |
| Fetch a visitor's persisted session messages | Anyone (no sign-in) (public) |
| Framable chat document for a share link | Anyone (no sign-in) (public) |
| Read a documentation page by slug | Anyone (no sign-in) (public) |
| Resolve a share link to limited agent info | Anyone (no sign-in) (public) |
| Resume a running shared task's event stream | Anyone (no sign-in) (public) |
| Search public documentation | Anyone (no sign-in) (public) |
What isn't here
Platform-operations capabilities — managing tenants, the global model registry and its pricing, self-hosted endpoints, and cross-organization skill publishing — are held by Delegate's own staff and are not part of any customer role. What support staff can see in your organization, and how to switch it off, is covered in Support access & auditing.