Skip to main content
Sign inDownload

Permissions

Workspace admins set agent policy per role in Settings → Permissions. Members inherit the bundle for their role. They cannot raise their own ceiling from the chat composer.

Tool classes use Deny, Require approval, or Allow from the outline control. Grant approvals is a privilege checkbox, not a tool row.

Open Permissions

  1. Open Settings from the footer account menu.
  2. Select Permissions in the settings rail (its own section, not under Team).

You need manage team or an admin role to edit bundles. Everyone else sees read-only policy.

Role tabs

The strip runs Admin → Creator → Editor → Viewer, plus any custom roles you add. Pick a tab to edit that role only. Changes save for the whole workspace.

Reset to default restores the built-in bundle for the active tab.

Agent chat modes

Checkboxes set which chat modes the role may pick in the composer:

ModeTypical use
Read onlySafest. Table reads only
AskDefault posture. Risky tools pause for approval
Allow sessionWider session allowance after confirm
Full accessWidest Appenda tool allowance (Admin / Creator only by default)

Members only see modes their role allows. Full access is hidden for Viewer and Editor unless an admin enables it.

Tools

Each row is a tool class with Deny, Require approval, or Allow:

Tool classCovers
Tables (read)Read tools on table data
Tables (write)Row mutations
Tables (create/delete)Create or delete tables
Fields (add/delete)Schema changes on a table
List importSearch jobs that add many rows
Enrichment runPaid provider column runs
Agent filesystemNative adapter file access (off by default)
Agent terminalNative adapter shell access (off by default)

Editor defaults (typical): list import Allow, enrichment Require approval, agent filesystem and terminal Deny. Admin and Creator match similar safe defaults for native adapter tools.

Require approval sends the turn to an approval card when the active chat mode does not already auto-allow the call.

Runs without approval

Rows per run caps how many rows a role may touch in one enrichment or bulk write before an approval card appears, even when the tool class is Allow.

Privileges

Privileges are separate checkboxes. They gate workspace admin actions, not a single agent tool call:

PrivilegeMeaning
Invite membersSend workspace invites
Manage teamEdit roles and Permissions
Create API keysWorkspace API keys
Export listsTable export actions
Delete workspaceDestructive workspace delete
Manage agent accessProvider allowlists under Settings → Agents
Grant approvalsResolve pending approval requests and save durable grants
Configure integrationsIntegration policy under Settings → Integrations
Manage billingPlan and billing screens

Grant approvals is a privilege only. It does not appear as a Deny / Require approval / Allow tool row.

How Permissions fits chat and approvals

LayerWhereWhat it controls
PermissionsSettings → PermissionsRole ceilings for modes and tool classes
Chat modeAgent composerSession posture for this tab
Runtime cardsIn chatOne tool call that still needs an answer

Chat mode cannot bypass Deny. Require approval still shows cards unless the mode and run limits already cleared the call.

FAQs

Why can't I edit Permissions?
Only workspace admins and roles with Manage team can change bundles. Members read policy but cannot edit it.
Why does my Editor still see approval cards on enrichment?
Enrichment run is Require approval for Editor by default. Chat mode widens the session but does not downgrade that tool class to Allow.
Does Full access enable Claude or Cursor filesystem tools?
No. Agent filesystem and Agent terminal stay Deny for all built-in roles unless an admin changes them. Full access applies to Appenda table tools, not native adapter shell access.
Who can approve pending requests from other members?
Roles with Grant approvals or workspace admins. They review the queue under Settings → Agents.
Can I add a custom role?
Yes. Use Add role on the Permissions page and pick a built-in role to copy defaults from. Custom roles get their own tab in the strip.