{
  "title": "Role-based access control (RBAC)",
  "description": "Assign permissions to users through documented roles.",
  "slug": "role-based-access",
  "locale": "en",
  "seoTitle": "Role-based access control compatibility — Can My Agent Use",
  "socialTitle": "Role-based access control",
  "socialDescription": "Compare documented product roles and the permissions assigned to them.",
  "llmSummary": "Role-based access control assigns permissions to users through roles; possession of a shared link alone is not RBAC.",
  "audience": "Teams requiring least-privilege collaboration.",
  "contentKind": "feature",
  "status": "published",
  "tags": [
    "collaboration",
    "permissions",
    "RBAC",
    "teams"
  ],
  "updated": "2026-08-28T00:00:00.000Z",
  "published": "2026-08-28T00:00:00.000Z",
  "category": "collaboration",
  "summary": "Assign and enforce permissions through documented roles.",
  "specLabel": "Common product term",
  "aliases": [
    "RBAC",
    "team roles",
    "collaborator permissions"
  ],
  "capabilityKind": "atomic",
  "parent": "collaboration-and-portability",
  "related": [
    "admin-policy-controls",
    "audit-logs",
    "conversation-sharing"
  ],
  "relations": [],
  "highlight": false,
  "notes": [
    {
      "id": 2,
      "text": "Evidence checked 2026-08-28: Claude Enterprise custom roles can grant product capabilities, connector and model access, and delegated administration through group assignments. Organization settings are the upper gate, permissions are additive across roles, and only members whose organization role is Custom are governed by custom roles."
    },
    {
      "id": 3,
      "text": "Evidence checked 2026-08-28: Cursor documents team Member, Admin, and Unpaid Admin roles plus Enterprise organization groups that can map cohorts into teams with Member or Admin roles and apply model and agent controls. The role vocabulary is fixed rather than an arbitrary custom-role builder."
    },
    {
      "id": 4,
      "text": "Evidence checked 2026-08-28: Perplexity Enterprise supports base and custom roles assigned directly or through managed or SCIM groups. Roles grant product, sharing, file, API, security, and administrative permissions, while organization-level master switches remain separate."
    },
    {
      "id": 5,
      "text": "Evidence checked 2026-08-28: Replit provides Admin, Member, Guest, and Viewer roles plus Enterprise custom groups and app-specific Owner, Publisher, Editor, Viewer, and None access levels. Groups can receive access to selected apps; permissions differ between organization and app scope."
    }
  ],
  "issues": [],
  "resources": [
    {
      "title": "Methodology",
      "href": "/methodology",
      "kind": "note"
    },
    {
      "title": "NIST — Role Based Access Control",
      "href": "https://csrc.nist.gov/projects/role-based-access-control",
      "kind": "spec",
      "publisher": "NIST",
      "reviewedAt": "2026-08-28"
    },
    {
      "title": "OpenAI — Role-based access controls for ChatGPT Enterprise",
      "href": "https://help.openai.com/en/articles/11750701-rbac",
      "kind": "docs",
      "publisher": "OpenAI",
      "reviewedAt": "2026-08-28"
    },
    {
      "id": "anthropic-custom-roles",
      "title": "Anthropic Help Center — Manage custom roles on Enterprise plans",
      "href": "https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans",
      "kind": "docs",
      "publisher": "Anthropic",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Custom roles; precedence; capabilities and permissions"
    },
    {
      "id": "cursor-iam-rbac",
      "title": "Cursor Docs — Identity and access management",
      "href": "https://prod.cursor.com/docs/enterprise/identity-and-access-management",
      "kind": "docs",
      "publisher": "Cursor",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Role-Based Access Control"
    },
    {
      "id": "cursor-organization-groups",
      "title": "Cursor Docs — Organization Groups",
      "href": "https://prod.cursor.com/docs/enterprise/organization-groups",
      "kind": "docs",
      "publisher": "Cursor",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Set team roles from mappings; group settings"
    },
    {
      "id": "perplexity-enterprise-rbac",
      "title": "Perplexity Help Center — Enterprise roles and permissions",
      "href": "https://www.perplexity.ai/help-center/en/articles/11187754-enterprise-roles-and-permissions",
      "kind": "docs",
      "publisher": "Perplexity",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Roles and groups; access evaluation; permissions reference"
    },
    {
      "id": "replit-roles-groups-access",
      "title": "Replit Docs — Roles, groups, and access",
      "href": "https://docs.replit.com/teams/identity-and-access-management/groups-and-permissions",
      "kind": "docs",
      "publisher": "Replit",
      "evidenceType": "documented",
      "reviewedAt": "2026-08-28",
      "locator": "Roles; custom groups; app access control"
    }
  ],
  "support": [
    {
      "harness": "claude-web",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Claude Enterprise custom-role documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "custom roles are available to Enterprise organizations and apply only after a member's organization role is set to Custom"
            },
            {
              "type": "policy",
              "value": "roles assigned through groups can grant Chat and other capabilities, connectors and tools, models and effort limits, and delegated administration"
            },
            {
              "type": "runtime",
              "value": "organization-level settings are the upper gate and capability grants are additive across applicable custom roles"
            }
          ],
          "evidence": [
            {
              "resourceId": "anthropic-custom-roles",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "claude-desktop",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            2
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Claude Enterprise desktop role enforcement observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise custom roles can grant or restrict Chat access across web, desktop, and mobile for members whose organization role is Custom"
            },
            {
              "type": "policy",
              "value": "group-assigned roles also govern connectors, models, effort limits, and other supported capabilities; the most restrictive organization-level gate remains authoritative"
            }
          ],
          "evidence": [
            {
              "resourceId": "anthropic-custom-roles",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "cursor",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            3
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Cursor RBAC documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "policy",
              "value": "team Member, Admin, and Unpaid Admin roles separate product use from team and security administration"
            },
            {
              "type": "plan",
              "value": "Enterprise organization groups can map directory or manually managed cohorts to teams with Member or Admin roles and attach model and agent controls"
            },
            {
              "type": "runtime",
              "value": "roles are built in rather than arbitrary custom permission bundles, and group settings commonly use a most-permissive merge"
            }
          ],
          "evidence": [
            {
              "resourceId": "cursor-iam-rbac",
              "type": "documented",
              "observedAt": "2026-08-28"
            },
            {
              "resourceId": "cursor-organization-groups",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "perplexity-web",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            4
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Perplexity Enterprise RBAC documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "plan",
              "value": "Enterprise administrators can manage base and custom roles and assign them directly or through Perplexity-managed or SCIM-synced groups"
            },
            {
              "type": "policy",
              "value": "roles grant file, sharing, API, security, product, and administrative permissions; grants are additive across roles"
            },
            {
              "type": "runtime",
              "value": "organization-level feature and public-sharing controls remain master switches that roles cannot override"
            }
          ],
          "evidence": [
            {
              "resourceId": "perplexity-enterprise-rbac",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    },
    {
      "harness": "replit-agent",
      "versions": [
        {
          "track": "current",
          "status": "yes",
          "noteIds": [
            5
          ],
          "target": {
            "kind": "hosted-observation",
            "revision": "2026-08-28 Replit roles and app-access documentation observation",
            "observedAt": "2026-08-28"
          },
          "environmentProfile": "enterprise-managed",
          "qualifiers": [
            {
              "type": "policy",
              "value": "organization roles are Admin, Member, Guest, and Viewer; app access levels are Owner, Publisher, Editor, Viewer, and None"
            },
            {
              "type": "plan",
              "value": "Enterprise custom groups add fine-grained cohort access and can be synchronized from an identity provider"
            },
            {
              "type": "runtime",
              "value": "organization permissions and app-specific access are separate scopes, and groups receive app access through each app's Access panel"
            }
          ],
          "evidence": [
            {
              "resourceId": "replit-roles-groups-access",
              "type": "documented",
              "observedAt": "2026-08-28"
            }
          ]
        }
      ]
    }
  ],
  "html": "/features/role-based-access",
  "markdown": "/features/role-based-access.md",
  "json": "/api/v1/features/role-based-access.json",
  "body": "This row asks whether collaboration rights are enforced by role rather than inferred from possession of a link. Useful permission boundaries separate viewing prompts and files, editing context, starting runs, using billable models, invoking tools, approving actions, managing connectors or secrets, sharing externally, exporting, deleting, and administering policy.\n\nEvidence should record built-in and custom roles, project and organization scope, group mapping, temporary access, inheritance and exceptions, removal behavior for active runs, service identities, and audit attribution."
}