Roles & permissions
Endpoint AI access is a set of per-person role flags, so you can give someone exactly the console they need: read-only visibility, full management, audit access, or a single delegated profile.
The role flags
Roles are set per person on Manage users → edit user. When your account includes Endpoint AI, the provisioner roles appear there as Provisioner scopes checkboxes.
| Role | What it grants |
|---|---|
| View Harriet Provisioner | Read-only access to the console: devices, skills, and deployments. Good for IT staff who need visibility without change rights. |
| Manage Harriet Provisioner | Write access: assign skills and profiles, configure devices, change provisioner settings, send enrollment invites, and approve or deny skill requests. Includes everything View grants. |
| View provisioner audit and usage | Tool audit logs, dashboard metrics, and LLM usage analytics for the organization. Without it, the Dashboard charts and activity stream stay hidden. |
| View provisioner tool debug data | Stored tool arguments and results in the audit log, which may contain sensitive employee data. Works only in combination with View provisioner audit and usage; being an account owner alone is not enough. Error text in the log is visible with audit access alone. |
| Manage LLM budgets | Create and manage LLM spend budgets and alerts for the organization. |
| Access billing | Managed LLM credits, the billing summary, auto-top-up settings, and receipts. Deliberately independent: a finance person can hold this without any provisioner management or audit access. See credits. |
| Owner | Full access across the account. A few actions are owner-only regardless of other flags: toggling Store tool arguments and results in Settings, and granting the owner flag or tool debug access to others. |
| Super admin | Permission administration: may grant and revoke role flags for other users without holding full owner access. Lets each department have a local admin who manages permissions in their own area. |
| Manage skill group access | View all skills and control which groups and channels can use them, plus create skills and run bulk assignment, without full skill administration. |
| Review shared skills and MCPs | Approve, reject, and request changes for skills and MCP connectors in the review queue. |
Delegated management
Two forms of delegation grant scoped access without any of the flags above:
- Delegated skill managers. Each skill can name a management group; members of that group can edit that skill and configure its access, and only that skill.
- Delegated profile managers. Each profile can name management groups; members can open the Profiles screen and manage the profiles they are delegated for: editing skill assignments and connector configs, but not creating or deleting profiles. See delegated profile management.
Delegation is why direct flags stay rare in a healthy setup: the sales ops lead manages the sales profile without being able to touch anyone else's.
Who can grant roles
Owners and super admins can grant and revoke permission flags for other users. Two exceptions stay owner-only: the owner flag itself, and View provisioner tool debug data, which only an owner can grant. This keeps the most sensitive data path — reading tool arguments and results — behind a deliberate double gate: an owner must grant the role, and an owner must have enabled storage in Settings in the first place.
A useful default split: give IT View Harriet Provisioner plus View provisioner audit and usage, one or two admins Manage Harriet Provisioner, finance Access billing, and keep tool debug data granted to nobody until a support case actually needs it.