Roles & permissions

Endpoint AI access is a set of per-person role flags, so you can give someone exactly the console they need: read-only visibility, full management, audit access, or a single delegated profile.

The role flags

Roles are set per person on Manage users → edit user. When your account includes Endpoint AI, the provisioner roles appear there as Provisioner scopes checkboxes.

RoleWhat it grants
View Harriet ProvisionerRead-only access to the console: devices, skills, and deployments. Good for IT staff who need visibility without change rights.
Manage Harriet ProvisionerWrite access: assign skills and profiles, configure devices, change provisioner settings, send enrollment invites, and approve or deny skill requests. Includes everything View grants.
View provisioner audit and usageTool audit logs, dashboard metrics, and LLM usage analytics for the organization. Without it, the Dashboard charts and activity stream stay hidden.
View provisioner tool debug dataStored tool arguments and results in the audit log, which may contain sensitive employee data. Works only in combination with View provisioner audit and usage; being an account owner alone is not enough. Error text in the log is visible with audit access alone.
Manage LLM budgetsCreate and manage LLM spend budgets and alerts for the organization.
Access billingManaged LLM credits, the billing summary, auto-top-up settings, and receipts. Deliberately independent: a finance person can hold this without any provisioner management or audit access. See credits.
OwnerFull access across the account. A few actions are owner-only regardless of other flags: toggling Store tool arguments and results in Settings, and granting the owner flag or tool debug access to others.
Super adminPermission administration: may grant and revoke role flags for other users without holding full owner access. Lets each department have a local admin who manages permissions in their own area.
Manage skill group accessView all skills and control which groups and channels can use them, plus create skills and run bulk assignment, without full skill administration.
Review shared skills and MCPsApprove, reject, and request changes for skills and MCP connectors in the review queue.

Delegated management

Two forms of delegation grant scoped access without any of the flags above:

Delegation is why direct flags stay rare in a healthy setup: the sales ops lead manages the sales profile without being able to touch anyone else's.

Who can grant roles

Owners and super admins can grant and revoke permission flags for other users. Two exceptions stay owner-only: the owner flag itself, and View provisioner tool debug data, which only an owner can grant. This keeps the most sensitive data path — reading tool arguments and results — behind a deliberate double gate: an owner must grant the role, and an owner must have enabled storage in Settings in the first place.

💡

A useful default split: give IT View Harriet Provisioner plus View provisioner audit and usage, one or two admins Manage Harriet Provisioner, finance Access billing, and keep tool debug data granted to nobody until a support case actually needs it.