Skip to content

Roles and capabilities

Since 0.1.0

Access is governed by capabilities (named permissions) grouped into roles assigned to users. Ajutant ships these system roles; administrators can also create custom roles.

RoleWhat it can do
Power UserEveryday use: chat, documents, forms. No admin capabilities.
Assistant CreatorBuild and manage assistants they own.
Reporting UserView reporting: usage, costs, ROI, billing, feedback. No admin console.
ApproverApprove or reject changes submitted for approval.
Client AdminManage the platform: assistants, chatbots, models, knowledge, connections, users, teams, directories, roles, governance, distribution, settings, plus all reporting.
Platform AdminEverything (a super-role that implies all capabilities).

A capability unlocks one admin area or action, and the same capability gates both what you see and what the API allows, so visibility always matches access. Examples: manage_assistants, manage_governance, manage_models, manage_users, manage_roles, view_reporting, view_licenses.

A Client Admin can create a custom role with exactly the capabilities it needs, then assign it to users. This is how you fit access to your own structure rather than the system roles alone. See Users, teams, and roles.