Create a role and assign permissions
Creatio AI Studio controls access with role-based access control. A permission is a single capability, for example, reading agents or managing budgets. A role is a named bundle of permissions. A principal — a user, a service account, or a group — gets capabilities only by holding a role.
Grant capabilities to a role once, then assign the role to as many principals as you need. Change the role later and everyone who holds it updates at the same time.
Roles live in the Security section under Administration, on the Roles tab.
Create a role
-
Go to the Security section under Administration in the navigation panel.
-
Open the Roles tab.
-
Click New. This opens the "Create role" dialog.
-
Fill out the role fields.
Field
Field value
Name
Human-readable name of the role, for example, "Agent Reviewer."
Code
Stable identifier used by the platform, for example,
agent_reviewer. Creatio AI Studio generates it from the name and states that it cannot be changed later.Description
What the role is for. Add one so the next administrator understands its purpose.
-
Click Save.
As a result, Creatio AI Studio reports "Role saved" and adds the role to the Roles tab, which lists every role by name, code, and description. The role grants nothing until you add permissions.
Add permissions to the role
- Open the role from the Roles tab.
- Open the Permissions tab.
- Click Add permissions.
- Select the permissions the role grants. Permissions are grouped by area: Administration, Agents, Channels, Connections, Deployments, Development, Evaluations, Governance, Integrations, Knowledge, Operations, Prompts, Runs, Skills, and Tools. Use the Search permissions field to find one by name, or select the checkbox of a category to take the whole group.
- Click Save.
As a result, the role grants the selected permissions. Everyone who holds the role gains them immediately.
To remove a permission, select it on the Permissions tab and click Remove. Anyone assigned the role loses the permission immediately. You can add it back later.
Assign the role to principals
- Open the role from the Roles tab.
- Open the Principals tab.
- Click Assign. This opens the "Assign principals" dialog, with a tab each for Users, Groups, and Service Accounts.
- Select the users, service accounts, and groups that need the role.
- Click Assign.
As a result, Creatio AI Studio assigns the role and the principals gain its permissions. The Principals tab lists everyone who holds the role.
To remove a principal, select its row on the Principals tab, click Remove, and confirm.
A role can also receive access to an integration whose access is restricted. Add the role with Grant access on the Access tab of the integration. Users with Manage security can use every integration without a grant. Learn more: Integrations.
Deleting a role is not reversible. Every user, group, and service account assigned to it loses the permissions that only this role granted.