Understanding roles and permissions in WRITER

Last updated: September 12, 2026

Who can use this feature

  • Default roles are available to all WRITER accounts

  • Custom roles are supported on Enterprise plans

  • Custom roles can be created and modified by the org admin and business admin roles

Our roles and permissions system provides greater granularity and control, allowing organizations to manage access separately at the organization and team levels. With custom roles and a role-based access control system, you can precisely control who can configure key features like Knowledge Graphs and agents while improving security and scalability across your workspace.

Overview of roles in WRITER

Roles allow you to grant granular permissions to members of your organization, giving you precise control over who can access specific features and what they can do within the platform.

Access levels and role types

Each role gives a set of permissions that users can use at the organization or team level. Together, they decide how much control and access a user has to parts of the WRITER platform.

  • Org level permissions cover different areas, like user team and role management, billing and reporting, agent building, AI Studio access, and more.

    Team roles cover team specific permissions such as team membership management, managing team Knowledge Graphs, and more.

    Role Types (Default vs. Custom):

    • Default Roles: These are nine pre-made roles for the most common administrative and user needs, like managing a team or handling billing. Every Writer account starts with these.

    • Custom Roles: If the default roles aren't a perfect fit, you can build your own custom roles and choose the specific permissions you need.

      You can assign these roles at two different levels: for your whole organization and for a specific team.

Important: You often need to assign more than one role

A person may need multiple roles to perform their job. For example, someone might need one role to access their team’s settings and another to use AI Studio.

For instance, a marketing team manager who creates a custom chat agent needs two roles in WRITER:

  1. Team Admin to manage their team’s settings, library, and homepage.

  2. AI Studio builder to access AI Studio and build the chat agent. This role allows building but not deploying agents, which is handled by IT.

By assigning multiple roles, you can give people the exact access they need - no more, and no less. To learn how to assign roles to your users, see this section of this article.

Default roles

Definition of default roles

Use the tables below to understand the different default roles available in WRITER and the permissions associated with each role. Scroll to the right on the tables below to see full information.

Role Level Description Examples of who should have the role
Org admin Organization This role includes automatic access to all teams within the organization with team admin permissions. It also has broad admin access to org configuration for billing, users, teams, roles, account, authentication, style guide, and security. CISO, CTO, Operations Head, IT Manager, Department Head
AI Studio full access Organization This role allows users to build, create, and manage all agents, Knowledge Graphs, API keys, and voices within AI Studio. These users can deploy any agents and view consumption data. AI/ML Engineer, Data Scientist, Quantitative Analyst, Analytics Manager, AI Research Scientist
AI Studio builder Organization This role allows users to build and create agents, Knowledge Graphs, and voices within AI Studio. They can manage their own items, but can't view or manage those created by other users. These users cannot deploy own agents. AI/ML Engineer, Data Scientist, Business Intelligence Developer, Technical Lead, Research Scientist
AI Studio team admin Organization This role includes AI studio access for legacy team admin resources, such as knowledge graphs. Team Lead, Project Manager, Department Manager
AI Studio view only Organization This role offers limited, view-only access to agents, Knowledge Graphs, and voice. It can also access agents deployed to playground. This user cannot deploy or edit agents. Data Analyst, Business Analyst, Risk Analyst, Product Manager, Clinical Research Coordinator
Business admin Organization This role can manage business administration settings such as the style guide builder, user, and billing management. It can also access reporting, but does not have access to authentication or data and security settings. Business Operations Manager, Finance Manager, Business Analyst, Brand Manager
IT admin Organization This role can manage authentication and data and security settings. It can also manage AI Studio with full access to agents, API keys, Knowledge Graphs, and voices. IT Administrator, System Administrator, IT Manager, IT Director, Infrastructure Manager,
Team admin Team This role includes full access to team setup, including libraries, homepage, terms, suggestions, snippets, prompts, Knowledge Graphs, and voices. It can also add and remove members from the team and view usage reporting for this team. Team Lead, Project Manager, Department Manager
Team member Team Most users in your org will have the Team member role. This role includes basic membership to the team with ability to use agents, check content. It also has view-only access to suggestions, terms, and other settings within AI Studio. Individual contributors
Limited team member Team This role includes the same team membership as Team member, with the ability to use agents and run playbooks shared with them, but without the ability to create, edit, publish, or share playbooks, or set up playbook triggers. Use it when designated power users should build and maintain playbooks while everyone else only views and runs them. Individual contributors in orgs with centralized playbook governance, frontline or field staff, contractors and temporary users, users in cost-controlled teams

Please take note the team member role throughout this guide is based on being assigned a Pro seat. If a user is assigned a Lite seat they will have limited access to WRITER as follows:

  • Lite Seat users are able to use all end-user WRITER functionality (ex: can create and share skills & playbooks)

  • Lite Seat users can’t be assigned org-scoped roles

  • Lite Seat users can’t access AI Studio, team, or org settings

  • Lite Seat users are limited to the Team Member role

  • Lite Seat users can run no more than 1 concurrent agent session

Default role permissions

As an org admin you can assign multiple org and team level roles to give your users the permissions in WRITER that they require. The tables below will show you the granular permission each default role has enabled. To learn how to create custom roles for your WRITER account click here.

User, team, and role management permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
View users (team only) (team only) (team only)
Invite and manage users (team only)
View teams (team only)
Manage teams (team only)
View roles (team only)
Manage roles (team only)

Billing and reporting permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
View billing groups
Manage billing groups
View and manage billing
View usage reporting (team only)
View admin audit log (team only)

Account and style guide permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
Manage account settings
Manage style guide (team only)

Data, security access, and provisioning permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
Manage access and provisioning
Manage data and web use
Manage OAuth apps

AI Studio permissions:

Permission Org admin AI Studio full access AI Studio builder AI studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
View no-code agents
View templates
Create agent from template
Duplicate existing no-code agent
Create no code agent
Delete draft agent - created by self
Delete draft agent - created by anyone
Modify no code agent (draft) - created by self
Modify any no code agent
Deploy own agents
Deploy agents created by anyone
Push changes (deploy current draft of existing agent)
Regenerate embed token for no code agent
API keys (create, revoke, view secret, etc)
Framework agents (create, revoke, view secret, etc)
Open agents in playground & copy playground URL
Enable/disable playground - agent created by self
Enable/disable playground - all agents
Create Knowledge Graph
Create Voice
Modify/delete KG - created by self
Modify/delete Voice - created by self
Modify/delete KG - created by anyone
Modify/delete Voice - created by anyone
Invite user to AI Studio
Delete AI Studio user
Change user AI Studio roles
CRUD Billing details
View analytics (when released)

AI Studio billing and reporting permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
View and manage billing
View consumption
View and manage session logs

Team specific permissions:

Permission Org admin AI Studio full access AI Studio builder AI Studio team admin AI Studio view only Business admin IT admin Team admin Team member Limited team member
Manage team terms
View team terms
Manage team suggestions and tools
View team suggestions and tools
Create and manage team snippets
View team snippets
Create and manage team Knowledge Graphs
View team Knowledge Graphs
Create and manage team voices
View team voice
Create and manage team prompts
View team prompts
View team users
Manage team users
Manage team details
Create and edit team library
Configure team homepage

Feature permissions for team-level roles:

Feature

Team member

Limited team member

Docs and Editor

View and use

View and use

Agent Library

View and use

View and use

My Work

View and use

View and use

WRITER Agent

View and use

View and use

Playbooks

View and use playbooks shared with them;

Create and share playbooks with others

View and use playbooks shared with them

Playbook triggers

View and use in playbooks shared with them;

Set up and manage triggers in playbooks they create

View and use in playbooks shared with them

Skills

View and use

View and use

Suggestions and tools

View

View

Terms

View

View

Snippets

View

View

Voice

View (can create/use personal voice)

View (can create/use personal voice)

Knowledge Graph

View

View

Team users

View

View

How to create a custom role

You can create custom roles at the organization level as well as for specific teams:

Select the Org settings and then the Users, teams & roles option from the Admin settings menu. From there, select the Roles tab and then + New role.

To create an org-level custom role:

  1. Give your custom role a clear name.

  2. Select Org level.

  3. Provide a description so other admins know when to assign the custom org-level role.

  4. On the right, select the specific org-level permissions you’d like this custom level to have.

  5. Select Save. Your new org-level custom role will now be visible under Org settings > Users, teams & roles > Roles.

To create a team-level custom role:

  1. Give your team-level role a clear name.

  2. Select Team level.

  3. Provide a description so other admins know when to assign the custom team-level role.

  4. On the right, select the specific team-level permissions you’d like this custom level to have.

  5. Select Save. Your new team-level custom role will now be visible under Org settings > Users, teams & roles > Roles.

Just want to make a slight tweak to an existing access role?

  1. Select Copy from in the top right to fill in the default permissions for an existing role.

  2. Give your adjusted role a new name and description.

  3. Adjust the permissions.

  4. Select Save. Your new custom role will now be visible under Org settings > Users, teams & roles > Roles.

How to assign roles to users

When you invite a user from Org settings > Users, teams and roles > Users, you can assign them any of the default or custom roles within your WRITER org.

  • From the invitation module, enter an email for the user you’d like to invite to your WRITER account.

  • (Optional) Next, select an option from the Billing group dropdown to associate the user with. To learn more about billing groups, click here.

  • Under Org permissions, assign any default or custom org-level roles to the user. You can select assign multiple org-level roles to a user.

  • Under Team permissions, select the team(s) the user should belong to. For each team, assign team-level permissions to the user. You can select multiple team-level roles to a user.

Additionally you can have roles and permissions automatically set for your users by setting up SCIM provisioning, learn more here.

FAQs

How do I assign new roles to existing users?

To change a single user’s role, navigate to Admin settings > Users, teams & roles > Users, select the ••• three dot menu to the right of a user’s name. Select Edit user details to make adjustments to their org-level or team-level access roles.

To edit user roles in bulk within the Users page, search or filter to find the users you’d like and then select the check box on the right of their email address. This will activate the bulk menu where you can select the Select action button to activate the menu and select Edit org role.

Please note, the maximum number of users that can be selected for bulk actions is 1000.

Select the role(s) you want to remove or add to your users and select Save and your changes will be applies.

You can also manage user roles in bulk by following the steps in your IdP to update the org and team role mapping. Learn more about SCIM provisioning here.

We are an existing WRITER customer. How should we migrate our current users to this new role system?

At rollover, there will be a 1:1 change of Org admins to the org admin role, and team admins to the new team admin role, and users to users.

Org admin → Org Admin, Team Admin → Team Admin, Team member → Team member, etc

There is only one significant change between the previous roles and the new roles:

Previously, team admins could manage changes to a published styleguide.com website. Now, styleguide.com website management is an org-level permission. If you wish to provide your team admins with access to this permission, you’ll need to create a custom role.

What is the difference between an organization-level role and a team-level role?

Organization-level roles (e.g., Org Admin, IT Admin) grant permissions that affect the entire Writer account, such as billing, security settings, and organization-wide user management. Team-level roles (e.g., Team Admin, Team Member) grant permissions that only apply within a specific team, like managing team members or accessing team-specific content..

What is the difference between a team member and a limited team member?

A limited team member has the same team membership and platform access as a team member, including the ability to use agents and run shared playbooks. The only difference is playbook permissions. A team member can create, publish, and manage their own playbooks, share playbooks with people and teams, and set up and manage playbook triggers. A limited team member can view and run playbooks shared with them, but cannot create, edit, publish, or share playbooks, or set up playbook triggers.

Choose the limited team member role when your organization needs strict centralized control over who builds and publishes playbooks. For example, if a few designated builders should own playbook creation while everyone else simply runs shared workflows, assign those builders the team member role and assign the rest the limited team member role.

How do I handle role changes for users with multiple team memberships?

Team membership is separate from org level roles. For example, if you remove an admin type role from a user they will still maintain their team member status for the teams they belong to. You can edit team membership from the Users tab or you can navigate to the Teams section to adjust team level membership and permissions.

Can I make changes to custom roles after they are created and assigned to users?

Yes, from the Roles tab, select the three dot icon on the right side of the role you’s wish to edit, and then select Edit role. From the role creation module that appears, make the changes you’d like and then select Save. The changes will now be live for any users you’ve assigned to the role. Default roles cannot be edited or deleted.

What happens if a user is assigned multiple roles? How do permissions combine?

When a user has multiple roles, their permissions are additive. They gain the combined total of all permissions from every role they are assigned. For example, if Role A grants permission to view users and Role B grants permission to create agents, a user with both roles can do both.

Can I delete a custom role after it's been created? What happens to the permissions of the users assigned to those roles if I do?

If a custom role is deleted, any users assigned to that role will lose the permissions granted by it. If they are not assigned to any other roles, they will revert to the default "Team member" permissions. We recommend reassigning users to a new role before deleting an old one.

How do roles assigned via SCIM/IdP interact with roles assigned manually in WRITER?

For users provisioned via SCIM, your Identity Provider (IdP) is the source of truth. Roles should be managed there. Any manual role changes made in the Writer UI for a SCIM-managed user will be overwritten during the next sync.

Are there any limitations on the number of custom roles I can create?

The maximum number of custom roles per WRITER org is 100 (team-level or org-level, cumulatively).

Can I temporarily suspend or revoke a user's role?

Yes. To temporarily suspend a user's permissions, you can edit their profile and remove the assigned role(s). Their access will be revoked immediately. To restore access, simply re-assign the role(s) at a later time. This is a non-destructive action.

Is there a way to audit or log changes made to roles and permissions?

Yes. The Admin audit log, accessible to org admins and IT admins, records all significant actions, including the creation, modification, and deletion of roles, as well as changes to user role assignments.

What are some best practices for setting up roles?

We recommend the following best practices:

  1. Start with the principle of least privilege: Only grant users the minimum permissions they need to perform their job.

  2. Leverage default roles first: Before creating a custom role, check if a combination of our default roles can meet your needs.

  3. Use a clear naming convention: When creating custom roles, use descriptive names like 'Marketing Content Approver' or 'Sales Agent Builder' to make them easily identifiable.

  4. Audit regularly: Periodically review your roles and user assignments to ensure they are still appropriate as your organization evolves.

I assigned a role to a user, but they still can't access what they need. What should I do?

This usually happens when a user is missing a required combination of roles. The most common reason is that they have a team-level role (like Team Admin) but are missing the necessary org-level role to access the area of the platform (like AI Studio - View Only).

Troubleshooting Steps:

Check all roles assigned to the user as well as their team membership. Confirm they have both an org-level role for platform access and a team-level role for specific content management.