---
title: "Role-based access control (RBAC)"
canonical: "https://canmyagentuse.com/features/role-based-access"
contentKind: "feature"
locale: "en"
description: "Assign permissions to users through documented roles."
llmSummary: "Role-based access control assigns permissions to users through roles; possession of a shared link alone is not RBAC."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["collaboration","permissions","RBAC","teams"]
---

# Role-based access control (RBAC)

Role-based access control assigns permissions to users through roles; possession of a shared link alone is not RBAC.

- HTML: https://canmyagentuse.com/features/role-based-access
- JSON: https://canmyagentuse.com/api/v1/features/role-based-access.json
- Markdown: https://canmyagentuse.com/features/role-based-access.md

Terminology basis: **Common product term** — https://csrc.nist.gov/projects/role-based-access-control.

## Current support at a glance

Role-based access control (RBAC): 5 supported, 0 partial, 0 unsupported, 26 unreviewed across 31 cataloged products.

- Reviewed current products: 5 of 31
- Supported: 5
- Partial: 0
- Unsupported: 0
- Unreviewed: 26
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

This row asks whether collaboration rights are enforced by role rather than inferred from possession of a link. Useful permission boundaries separate viewing prompts and files, editing context, starting runs, using billable models, invoking tools, approving actions, managing connectors or secrets, sharing externally, exporting, deleting, and administering policy.

Evidence should record built-in and custom roles, project and organization scope, group mapping, temporary access, inheritance and exceptions, removal behavior for active runs, service identities, and audit attribution.

## Catalog context

- Category: [collaboration](/categories/collaboration.md)
- Terminology basis: Common product term
- Aliases: RBAC, team roles, collaborator permissions
- Family: [Collaboration](/features/collaboration-and-portability.md)
- Siblings: [Artifact export](/features/artifact-export.md), [Conversation export](/features/conversation-export.md), [Conversation sharing](/features/conversation-sharing.md), [Shared projects](/features/shared-projects.md)

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise custom-role documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): custom roles are available to Enterprise organizations and apply only after a member's organization role is set to Custom
  - Constraint (policy): roles assigned through groups can grant Chat and other capabilities, connectors and tools, models and effort limits, and delegated administration
  - Constraint (runtime): organization-level settings are the upper gate and capability grants are additive across applicable custom roles
  - Evidence: [Anthropic Help Center — Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Claude Enterprise custom roles can grant product capabilities, connector and model access, and delegated administration through group assignments. Organization settings are the upper gate, permissions are additive across roles, and only members whose organization role is Custom are governed by custom roles.
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Unknown**

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Perplexity Enterprise RBAC documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise administrators can manage base and custom roles and assign them directly or through Perplexity-managed or SCIM-synced groups
  - Constraint (policy): roles grant file, sharing, API, security, product, and administrative permissions; grants are additive across roles
  - Constraint (runtime): organization-level feature and public-sharing controls remain master switches that roles cannot override
  - Evidence: [Perplexity Help Center — Enterprise roles and permissions](https://www.perplexity.ai/help-center/en/articles/11187754-enterprise-roles-and-permissions) — documented; observed 2026-08-28
  - Qualification note 4: Evidence checked 2026-08-28: Perplexity Enterprise supports base and custom roles assigned directly or through managed or SCIM groups. Roles grant product, sharing, file, API, security, and administrative permissions, while organization-level master switches remain separate.
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Replit roles and app-access documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (policy): organization roles are Admin, Member, Guest, and Viewer; app access levels are Owner, Publisher, Editor, Viewer, and None
  - Constraint (plan): Enterprise custom groups add fine-grained cohort access and can be synchronized from an identity provider
  - Constraint (runtime): organization permissions and app-specific access are separate scopes, and groups receive app access through each app's Access panel
  - Evidence: [Replit Docs — Roles, groups, and access](https://docs.replit.com/teams/identity-and-access-management/groups-and-permissions) — documented; observed 2026-08-28
  - Qualification note 5: Evidence checked 2026-08-28: Replit provides Admin, Member, Guest, and Viewer roles plus Enterprise custom groups and app-specific Owner, Publisher, Editor, Viewer, and None access levels. Groups can receive access to selected apps; permissions differ between organization and app scope.
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise desktop role enforcement observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise custom roles can grant or restrict Chat access across web, desktop, and mobile for members whose organization role is Custom
  - Constraint (policy): group-assigned roles also govern connectors, models, effort limits, and other supported capabilities; the most restrictive organization-level gate remains authoritative
  - Evidence: [Anthropic Help Center — Manage custom roles on Enterprise plans](https://support.claude.com/en/articles/13930452-manage-custom-roles-on-enterprise-plans) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Claude Enterprise custom roles can grant product capabilities, connector and model access, and delegated administration through group assignments. Organization settings are the upper gate, permissions are additive across roles, and only members whose organization role is Custom are governed by custom roles.
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Cursor RBAC documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (policy): team Member, Admin, and Unpaid Admin roles separate product use from team and security administration
  - Constraint (plan): Enterprise organization groups can map directory or manually managed cohorts to teams with Member or Admin roles and attach model and agent controls
  - Constraint (runtime): roles are built in rather than arbitrary custom permission bundles, and group settings commonly use a most-permissive merge
  - Evidence: [Cursor Docs — Identity and access management](https://prod.cursor.com/docs/enterprise/identity-and-access-management) — documented; observed 2026-08-28
  - Evidence: [Cursor Docs — Organization Groups](https://prod.cursor.com/docs/enterprise/organization-groups) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Cursor documents team Member, Admin, and Unpaid Admin roles plus Enterprise organization groups that can map cohorts into teams with Member or Admin roles and apply model and agent controls. The role vocabulary is fixed rather than an arbitrary custom-role builder.
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Unknown**
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Unknown**
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Unknown**
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Unknown**
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Unknown**
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
