Product feature · collaboration

Role-based access control (RBAC)Common product term

Assign and enforce permissions through documented roles.

Terminology basis: Common product term. NIST — Role Based Access Control

Role-based access control (RBAC): 5 supported, 0 partial, 0 unsupported, 26 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in Collaboration4 capabilities

Current evidence by product

Can my agent use Role-based access control (RBAC)?

Read across for the answer. 5 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported5
  • Partial0
  • Unsupported0
  • Unknown26
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

This row asks whether collaboration rights are enforced by role rather than inferred from possession of a link. Useful permission boundaries separate viewing prompts and files, editing context, starting runs, using billable models, invoking tools, approving actions, managing connectors or secrets, sharing externally, exporting, deleting, and administering policy.

Evidence should record built-in and custom roles, project and organization scope, group mapping, temporary access, inheritance and exceptions, removal behavior for active runs, service identities, and audit attribution.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Claudeweb · current
Supported
Target
2026-08-28 Claude Enterprise custom-role documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • plancustom roles are available to Enterprise organizations and apply only after a member's organization role is set to Custom
  • policyroles assigned through groups can grant Chat and other capabilities, connectors and tools, models and effort limits, and delegated administration
  • runtimeorganization-level settings are the upper gate and capability grants are additive across applicable custom roles
Claudedesktop · current
Supported
Target
2026-08-28 Claude Enterprise desktop role enforcement observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise custom roles can grant or restrict Chat access across web, desktop, and mobile for members whose organization role is Custom
  • policygroup-assigned roles also govern connectors, models, effort limits, and other supported capabilities; the most restrictive organization-level gate remains authoritative
Cursordesktop · current
Supported
Target
2026-08-28 Cursor RBAC documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • policyteam Member, Admin, and Unpaid Admin roles separate product use from team and security administration
  • planEnterprise organization groups can map directory or manually managed cohorts to teams with Member or Admin roles and attach model and agent controls
  • runtimeroles are built in rather than arbitrary custom permission bundles, and group settings commonly use a most-permissive merge
Evidence
Perplexityweb · current
Supported
Target
2026-08-28 Perplexity Enterprise RBAC documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise administrators can manage base and custom roles and assign them directly or through Perplexity-managed or SCIM-synced groups
  • policyroles grant file, sharing, API, security, product, and administrative permissions; grants are additive across roles
  • runtimeorganization-level feature and public-sharing controls remain master switches that roles cannot override
Evidence
Replit Agentweb · current
Supported
Target
2026-08-28 Replit roles and app-access documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • policyorganization roles are Admin, Member, Guest, and Viewer; app access levels are Owner, Publisher, Editor, Viewer, and None
  • planEnterprise custom groups add fine-grained cohort access and can be synchronized from an identity provider
  • runtimeorganization permissions and app-specific access are separate scopes, and groups receive app access through each app's Access panel
Evidence
  1. 2. Evidence checked 2026-08-28: Claude Enterprise custom roles can grant product capabilities, connector and model access, and delegated administration through group assignments. Organization settings are the upper gate, permissions are additive across roles, and only members whose organization role is Custom are governed by custom roles.
  2. 3. Evidence checked 2026-08-28: Cursor documents team Member, Admin, and Unpaid Admin roles plus Enterprise organization groups that can map cohorts into teams with Member or Admin roles and apply model and agent controls. The role vocabulary is fixed rather than an arbitrary custom-role builder.
  3. 4. Evidence checked 2026-08-28: Perplexity Enterprise supports base and custom roles assigned directly or through managed or SCIM groups. Roles grant product, sharing, file, API, security, and administrative permissions, while organization-level master switches remain separate.
  4. 5. Evidence checked 2026-08-28: Replit provides Admin, Member, Guest, and Viewer roles plus Enterprise custom groups and app-specific Owner, Publisher, Editor, Viewer, and None access levels. Groups can receive access to selected apps; permissions differ between organization and app scope.