Skip to main content

Roles and Permissions

Use Users → Roles to define which product areas people can open and which actions they can perform. A user can have more than one role; their effective permissions are the combined permissions granted by all assigned roles.

Access to the Roles tab and its management actions requires the Assign roles permission. Hiding a page or action in the Web App does not replace backend authorization: the same effective permissions are enforced when protected operations are requested.

Role Overview​

The Roles tab lists the role name, active members, and whether the role is built in. Use search to find a role, select its name to open the detail, or select Create role to add a custom role.

Select any screenshot to open it at full resolution.

Roles tab with built-in roles and the Create role action

Siesta AI provides four built-in roles. Use this summary to choose a starting point, then review the exact permission selection in the role detail:

RoleGood starting point forImportant boundaries
OwnerOrganization ownership and highest-impact security decisionsAlways has every permission, is read-only, and only another Owner can add or remove it.
AdminUser administration, organization configuration, reporting, and broad product managementDoes not receive Assign roles, billing management, or Entra team synchronization by default.
EditorPeople who build and maintain agents, workflows, Data, Memory, and other shared contentDoes not receive user administration, organization settings, analytics, audit log, or API key management by default.
UserPeople who chat, run assigned work, and use resources shared with their teamsReceives standard use capabilities but not tenant-wide administration.

Built-in role identities cannot be renamed or deleted. Custom roles belong to the organization and can be deleted when they are no longer needed.

Creating a Custom Role​

  1. Open Users → Roles and select Create role.
  2. Enter a unique role Name. The built-in names Owner, Admin, Editor, and User are reserved.
  3. Select permissions from the grouped permission tree.
  4. Optionally select initial members.
  5. Select Create role.

Complete Create Role form with permissions filtered to Agents

Permissions can depend on a parent permission. For example, an edit or delete action can require permission to view the same resource. Selecting a child permission automatically keeps its required parent selected; removing a parent also removes dependent permissions.

You cannot create or update a role with permissions you do not hold yourself. This prevents a role manager from granting a higher level of access than their own.

Editing Permissions​

Open a role and expand a permission group to review its individual actions. The group checkbox selects or clears the permissions that you are allowed to grant, and search opens matching groups. Select Save permissions after making changes.

Admin role with permissions filtered to Agents and the Save permissions button

The Owner detail is intentionally different: every catalog permission is selected and editing is disabled because Owner access is resolved automatically.

Owner role detail showing the read-only warning

Complete Permission Catalog​

The tables below mirror the stable keys, display names, dependencies, and built-in defaults defined by the backend. Owner is not repeated in the Default roles column because Owner always resolves to every catalog permission. None means that no non-Owner built-in role receives the permission by default; an Owner can still grant it to an appropriate custom role.

Custom roles start without built-in defaults. The app sends their selected keys to the backend. For Admin, Editor, and User, changes are stored as deviations from the defaults below.

Content and agent configuration​

AreaPermission keyApp labelDefault rolesRequires
CategoriesCategories.ViewViewAdmin, Editor, User—
CategoriesCategories.ManageManageAdmin, EditorCategories.View
SkillsSkills.ViewViewAdmin, Editor, User—
SkillsSkills.DeleteDeleteAdmin, EditorSkills.View
SkillsSkills.EditCreate & editAdmin, EditorSkills.View
SkillsSkills.ManageAccessShare with teamsAdmin, EditorSkills.Edit
PromptsPrompts.ViewViewAdmin, Editor, User—
PromptsPrompts.EditCreate & editAdmin, EditorPrompts.View
PromptsPrompts.DeleteDeleteAdmin, EditorPrompts.View
AgentsAgents.ViewViewAdmin, Editor, User—
AgentsAgents.DeleteDeleteAdmin, EditorAgents.View
AgentsAgents.UsePrivateConnectionsUse own private connectionsAdmin, Editor, UserAgents.View
AgentsAgents.UsePlatformToolsUse platform tools in chatAdminAgents.View
AgentsAgents.EditCreate & editAdmin, EditorAgents.View
AgentsAgents.ManageAccessShare with teamsAdmin, EditorAgents.Edit
AgentsAgents.ManageInterfaceMake publicly accessibleAdminAgents.Edit
TemplatesTemplates.ViewViewAdmin, Editor, User—
TemplatesTemplates.DeleteDeleteAdmin, EditorTemplates.View
TemplatesTemplates.EditCreate & editAdmin, EditorTemplates.View
TemplatesTemplates.ManageAccessShare with teamsAdmin, EditorTemplates.Edit
TemplatesTemplates.PublishPublish to the galleryAdminTemplates.Edit
MemoryMemory.ViewViewAdmin, Editor, User—
MemoryMemory.DeleteDeleteAdmin, EditorMemory.View
MemoryMemory.EditCreate & editAdmin, EditorMemory.View
MemoryMemory.ManageAccessShare with teamsAdmin, EditorMemory.Edit

Work and knowledge​

AreaPermission keyApp labelDefault rolesRequires
TasksTasks.ViewViewAdmin, Editor, User—
TasksTasks.DeleteDeleteAdmin, Editor, UserTasks.View
TasksTasks.RunRunAdmin, Editor, UserTasks.View
TasksTasks.EditCreate & editAdmin, Editor, UserTasks.View
TasksTasks.ManageAccessShare with teamsAdmin, EditorTasks.Edit
WorkflowsWorkflows.ViewViewAdmin, Editor, User—
WorkflowsWorkflows.DeleteDeleteAdmin, EditorWorkflows.View
WorkflowsWorkflows.RunRunAdmin, EditorWorkflows.View
WorkflowsWorkflows.EditCreate & editAdmin, EditorWorkflows.View
WorkflowsWorkflows.ManageAccessShare with teamsAdmin, EditorWorkflows.Edit
GraphsGraphs.ViewViewAdmin, Editor, User—
GraphsGraphs.DeleteDeleteAdmin, EditorGraphs.View
GraphsGraphs.EditCreate & editAdmin, EditorGraphs.View
GraphsGraphs.ManageAccessShare with teamsAdmin, EditorGraphs.Edit
Data sourcesDataSources.ViewViewAdmin, Editor, User—
Data sourcesDataSources.DeleteDeleteAdmin, EditorDataSources.View
Data sourcesDataSources.ManageLimitsManage upload limitsAdminDataSources.View
Data sourcesDataSources.EditCreate & editAdmin, EditorDataSources.View
Data sourcesDataSources.ManageAccessShare with teamsAdmin, EditorDataSources.Edit

Conversations, applications, and integrations​

AreaPermission keyApp labelDefault rolesRequires
RecordingsRecordings.ManageFull accessAdmin, Editor, User—
RecordingsRecordings.ShareShare via public linkAdmin, Editor, UserRecordings.Manage
RecordingsRecordings.ManageAccessShare with teamsAdmin, EditorRecordings.Manage
ConversationsConversations.ViewViewAdmin, Editor, User—
ConversationsConversations.DeleteDeleteAdmin, EditorConversations.View
ConversationsConversations.ChatChatAdmin, Editor, UserConversations.View
ConversationsConversations.ShareShare via public linkAdmin, EditorConversations.Chat
WebhooksWebhooks.ViewView ownAdmin, Editor—
WebhooksWebhooks.EditCreate & edit ownAdmin, EditorWebhooks.View
WebhooksWebhooks.DeleteDelete ownAdmin, EditorWebhooks.View
WebhooksWebhooks.ManageAllManage everyone'sAdminWebhooks.View
ConnectionsConnections.ViewViewAdmin, Editor, User—
ConnectionsConnections.DeleteDeleteAdmin, Editor, UserConnections.View
ConnectionsConnections.ManageLimitsManage token limitsAdminConnections.View
ConnectionsConnections.ManageSystemDefaultManage the shared default connectionAdmin, EditorConnections.View
ConnectionsConnections.EditCreate & editAdmin, Editor, UserConnections.View
ConnectionsConnections.ManageAccessShare with teamsAdmin, EditorConnections.Edit
System toolsSystemTools.ViewViewAdmin, Editor—
Live transcriptionLiveTranscription.UseUseAdmin, Editor, User—

Organization administration and reporting​

AreaPermission keyApp labelDefault rolesRequires
API keysApiKeys.ViewViewAdmin—
API keysApiKeys.ManageCreate & deleteAdminApiKeys.View
ContentContent.ImportImportAdmin—
BillingBilling.ManageManageNone—
TeamsTeams.ViewViewAdmin, Editor, User—
TeamsTeams.DeleteDeleteAdminTeams.View
TeamsTeams.EditCreate & editAdminTeams.View
TeamsTeams.ManageEntraSyncManage Entra group syncNoneTeams.Edit
UsersUsers.ViewViewAdmin—
UsersUsers.EditCreate & editAdminUsers.View
UsersUsers.DeleteDeleteAdminUsers.View
UsersUsers.InviteInvite peopleAdminUsers.View
UsersUsers.ManageRolesAssign rolesNoneUsers.View
OrganizationOrganization.AdminModeUse admin mode (see all data)Admin—
OrganizationOrganization.ViewViewAdmin, Editor, User—
OrganizationOrganization.ManageSettingsManage settingsAdminOrganization.View
OrganizationOrganization.ManageSecurityManage securityAdminOrganization.View
ReportingReporting.DashboardTeam dashboardAdmin, Editor, User—
ReportingReporting.FeedbackFeedbackAdmin, Editor—
ReportingReporting.AnalyticsOrganization analyticsAdmin—
ReportingReporting.AuditLogAudit logAdmin—
ReportingReporting.ToolExecutionsTool executionsAdmin—

The catalog shown in the app is authoritative for the current organization and deployed version. A route can require more than one permission—for example, Chat requires both Conversations.Chat and Agents.View. Resource access policies, organization feature switches, private-connection ownership, and provider permissions remain separate gates.

System Navigation and Permissions​

The documentation sidebar follows the current application System group: Profile, Organization, Analytics, Users, Logs, and Webhooks. The application hides or redirects protected entries according to effective permissions:

System entryPermission boundary
ProfileAccount, Apps & Extensions, and profile Security are available without a catalog permission after sign-in.
OrganizationThe entry is available when at least one Organization child page is available. General uses Organization.View; API Keys uses ApiKeys.View; Settings uses Organization.ManageSettings; Security uses Organization.ManageSecurity.
AnalyticsReporting.Analytics
UsersThe entry can lead to the first available tab: Users uses Users.View, Teams uses Teams.View, and Roles uses Users.ManageRoles.
LogsThe entry is available when Audit Log (Reporting.AuditLog) or Tool Executions (Reporting.ToolExecutions) is available.
WebhooksWebhooks.View

Assigning Members and Multiple Roles​

Assign members in either place:

  • Open a role, select its members, and choose Save members.
  • Open the action menu for a user in Users, choose the role assignment action, and select one or more roles.

Assign roles dialog for updating a user's complete role set

Permissions from multiple roles are additive: if any assigned role grants a permission, the user receives it. Removing a permission from one role does not remove the same permission when another assigned role still grants it.

Only an Owner can add or remove the Owner role. Other role managers can assign only roles whose complete permission set they hold themselves.

Editing and Deleting Safely​

  • The Owner role is read-only and always grants every permission.
  • A role that contains permissions stronger than your own is shown read-only to you.
  • Built-in roles cannot be deleted. Deleting a custom role removes its member assignments; a role assigned to a pending invitation must first be removed from that invitation.
  • Permission and membership changes affect every user assigned to the role. Verify sensitive changes with a test account before broad rollout.

Recommendations​

  • Create roles for durable job responsibilities, not individual people.
  • Prefer the smallest set of permissions needed for the work.
  • Separate ordinary resource use from high-impact actions such as role assignment, public interfaces, organization settings, billing, and security.
  • Review users with multiple roles because their effective access is the union of those roles.