Permissions
The Permissions tab shows the capabilities that can be added to a role. Permissions are defined by GESCON and cannot be created or edited from the interface.
Visible permissions
| Permission | What it allows |
|---|---|
| Agent Configuration Read | View agent configuration, for example to review instructions, tools, and knowledge sources without changing them. |
| Agent Configuration Write | Create, edit, and delete agents; for example, update an agent's instructions or assign a new source. |
| Documents Read | View documents allowed by the user's groups and folders; for example, open a synchronized contract preview. |
| Routes Read | View routes and tags, for example to select a route when starting a conversation. |
| Routes Write | Create, edit, and delete routes and tags; for example, reorganize documents in a topic route. |
| Sources Configuration Read | View how document, SQL, API, and MCP sources are configured without changing their settings. |
| Sources Configuration Write | Create, edit, and delete sources; for example, add a document synchronization or change which tables agents can use. |
| Connectors Read | View available connectors and their state, for example to check whether Microsoft Teams is enabled. |
| Users Read | View accounts and their assigned groups and roles, for example to check a person's access. |
| Users Write | Create, edit, and delete users; for example, change their groups or roles. |
| Roles Read | View roles and the permissions they contain without changing their composition. |
| Roles Write | Create, edit, and delete roles; for example, remove a capability from a custom role. |
| Groups Read | View groups, members, and associated resources, for example to review who can access a document collection. |
| Groups Write | Create, edit, and delete groups; for example, add users or assign a default agent. |
| Tenants Read | View general organization settings, such as its identity and available options. |
| Tenants Write | Change general organization settings, for example its name, image, or corporate preferences. |
| Knowledge Handler Read | View validated knowledge entries and their content. |
| Knowledge Handler Write | Create, edit, and delete validated knowledge; for example, turn a reviewed answer into a reusable entry. |
| Analytics Read | Access Analytics and AI Consultant results, for example to review usage, trends, and improvement opportunities. |
| Consultor IA Settings Write | Change AI Consultant sensitivity, schedule, and recipients; for example, schedule a weekly summary for selected managers. |
| Notices Read Write | Create and manage notices, for example to notify users or groups and attach related documents. |
| Global Skills Read Write | View and manage every skill in the organization, including skills outside the user's groups. |
| Group Skills Read Write | View and manage skills in the user's groups without extending access to the rest of the organization. |
If Marketplace is enabled, the interface may also show specific permissions for viewing the catalog, installing and reviewing content, publishing, and managing publications.
GESCON also contains internal permissions that do not appear on this screen and must not be assigned manually.
How they apply
- Create or edit a role.
- Select only the permissions needed for its function.
- Assign the role to users.
- Use groups to limit the specific content they can access.
Permissions grant a capability but do not override the scope of groups, sources, or resources. For example, Documents Read allows documents to be opened but does not grant access to folders that the user's group cannot view.
Separate read and write permissions whenever possible, and review roles when a person's responsibilities change.