Skip to main content

Permissions

The Permissions tab shows the capabilities that can be added to a role. Permissions are defined by GESCON and cannot be created or edited from the interface.

Visible permissions

PermissionWhat it allows
Agent Configuration ReadView agent configuration, for example to review instructions, tools, and knowledge sources without changing them.
Agent Configuration WriteCreate, edit, and delete agents; for example, update an agent's instructions or assign a new source.
Documents ReadView documents allowed by the user's groups and folders; for example, open a synchronized contract preview.
Routes ReadView routes and tags, for example to select a route when starting a conversation.
Routes WriteCreate, edit, and delete routes and tags; for example, reorganize documents in a topic route.
Sources Configuration ReadView how document, SQL, API, and MCP sources are configured without changing their settings.
Sources Configuration WriteCreate, edit, and delete sources; for example, add a document synchronization or change which tables agents can use.
Connectors ReadView available connectors and their state, for example to check whether Microsoft Teams is enabled.
Users ReadView accounts and their assigned groups and roles, for example to check a person's access.
Users WriteCreate, edit, and delete users; for example, change their groups or roles.
Roles ReadView roles and the permissions they contain without changing their composition.
Roles WriteCreate, edit, and delete roles; for example, remove a capability from a custom role.
Groups ReadView groups, members, and associated resources, for example to review who can access a document collection.
Groups WriteCreate, edit, and delete groups; for example, add users or assign a default agent.
Tenants ReadView general organization settings, such as its identity and available options.
Tenants WriteChange general organization settings, for example its name, image, or corporate preferences.
Knowledge Handler ReadView validated knowledge entries and their content.
Knowledge Handler WriteCreate, edit, and delete validated knowledge; for example, turn a reviewed answer into a reusable entry.
Analytics ReadAccess Analytics and AI Consultant results, for example to review usage, trends, and improvement opportunities.
Consultor IA Settings WriteChange AI Consultant sensitivity, schedule, and recipients; for example, schedule a weekly summary for selected managers.
Notices Read WriteCreate and manage notices, for example to notify users or groups and attach related documents.
Global Skills Read WriteView and manage every skill in the organization, including skills outside the user's groups.
Group Skills Read WriteView and manage skills in the user's groups without extending access to the rest of the organization.

If Marketplace is enabled, the interface may also show specific permissions for viewing the catalog, installing and reviewing content, publishing, and managing publications.

GESCON also contains internal permissions that do not appear on this screen and must not be assigned manually.

How they apply

  1. Create or edit a role.
  2. Select only the permissions needed for its function.
  3. Assign the role to users.
  4. Use groups to limit the specific content they can access.

Permissions grant a capability but do not override the scope of groups, sources, or resources. For example, Documents Read allows documents to be opened but does not grant access to folders that the user's group cannot view.

Least privilege

Separate read and write permissions whenever possible, and review roles when a person's responsibilities change.