Skip to main content
Workspace roles control what someone can do in that workspace. This is workspace RBAC—who can edit graphs, publish tools, or manage members—not Agent Card identity used for A2A exposure.
Agent Card describes how external agents discover your graph on the registry. Users & roles here govern Phinite workspace access only. See Agent Registry overview for card permissions.
The Summary is the fast view; the sections below spell out the same rules in more detail. Defaults can differ if your organization changes access. Roles: Super Admin, Admin, Developer, and QA are assigned per workspace. Viewer is described at the end—it is often used for read-only stakeholders. Legend: Yes means that role has the capability in the default setup; means it does not.

Summary


Workspace (create / view / change / delete)

Actions on the workspace itself (not Agent Graphs inside it).

Workspace navigation (sidebar)

Which items appear in the workspace left sidebar.

Workspace — Agent Graphs list

Creating and managing Agent Graphs from workspace home (not inside Graph Studio).

Workspace — Tools


Workspace — Integrations


Workspace — MCP servers


Workspace — Data sources


Workspace — Data source details


Workspace — API keys


Workspace — Users (members)


Billing & payments

Billing

Payments


Reports & workspace settings

Reports

Workspace settings

Profile (workspace scope)


Inside an Agent Graph — navigation

Sidebar sections when you open an Agent Graph in Graph Studio.

Graph versions (legacy flows UI)


Legacy Intents UI may still appear in older workspaces. New IA uses Triggers only—intent-specific rows below reflect historical permissions if your org has not migrated.

Intents (legacy)


Triggers


Agent Graph tools (configured tools)


Environment


Builds


Graph Studio — Auto Copilot


Graph Studio — Flow editor


Dev Studio — Auto Copilot


Dev Studio — Tool editor


Super Admin vs Admin

  • Super Admin can create, update, or delete the workspace, use the Billing sidebar entry, and change billing / payment records.
  • Admin matches Super Admin for building work and Users; Admins can view billing and payments but not the mutating actions above.

QA vs Developer

  • Developer can edit and publish in Graph Studio and Dev Studio per the tables above.
  • QA can run tests and open many views but not edit or publish Agent Graphs and tools.

Viewer role

Viewer is for read-only access. See Viewer. It is often configured outside the four workspace roles in this page.

Role detail pages

Roles are per workspace. The same person can be an Admin in one workspace and a Developer in another.