Skip to main content
Agent Studio has two account roles and three permission levels. Admins set a permission level for each area, in each project, for each Member.

Account roles

Wren is available to everyone who can open a project. Wren follows your per-area permissions in that project:
  • Wren can change only the areas where you have Edit.
  • To create a branch or apply changes, you need Edit on at least one area.
  • With Read on an area, you can ask Wren questions about it and explore it. Wren cannot change it.
  • To analyze conversations with Wren, you need Read on Conversations.
  • Wren cannot see areas set to None.

Permission levels

users-permissions Permission levels are set per project. A Member can have Edit on Knowledge in one project and None on Knowledge in another.

How the permission tree behaves

Areas are grouped in a tree. Each row has None, Read, and Edit options.
  • All is the first row. Select a level in the All row to apply it to every area in the project.
  • When you select a level on a top-level area, Agent Studio applies the same level to every item inside it.
  • When you select a level on a single item, only that item changes. The top-level area and the other items do not change.
  • A top-level area shows the level of its items when all items have the same level. When items have different levels, the top-level area shows None.
  • Conversations is an exception. Selecting a level on the Conversations row does not change the items inside it. Set PII, Call download, Intents, Entities, and Metrics one by one.
Set the All row first, then change the top-level areas that must differ, then expand an area to change single items.

Permission areas

The permission tree lists the areas below in this order. Each area has one line that says what it covers. If the area has items inside it, a table lists them. Select a level on an area to set every item inside it. Expand the area to set one item at a time. Some rows appear only when the related feature is enabled for the project.

Analytics

Analytics dashboards, metrics, and analysis.

Conversations

The conversation list, transcripts, and recordings. Selecting a level on this area does not set the items inside it. Set each item one at a time.

Custom dashboards

Managed dashboards that PolyAI builds and maintains in QuickSight for your organisation. With Edit, your team can also build these dashboards if QuickSight Authoring is enabled.

Behavior

The agent persona, rules, and settings.

Project context

Project documents that give the agent context.

Knowledge

FAQs, knowledge sources, and variants.

Flows

Conversation flows.

Tools

Custom functions and tools.

Test suite

Test cases, test sets, and test runs.

Real-time configuration

Real-time configuration and branches.

Voice

All voice channel settings.

Web chat

All web chat settings.

Integrations

App and API integrations.

Deployments

Environments, releases, and widgets.
There is no permission row for Home or for Wren. Wren follows the per-area permissions above. There is no permission row for workspace settings. Only Admins can open the Users, API keys, and Secrets pages under Manage workspace.

Set permissions

You set permissions when you add a user or when you edit a user. In both cases:
  1. On the Users page, open the Add users or Edit user panel.
  2. Select the Member role.
  3. In Projects, select each project that the user can open.
  4. Click a project row to expand it.
  5. For each area, select None, Read, or Edit. Expand an area to set single items.
  6. Click Add or Save.
To check the permissions of an existing user, click a project in the Projects column of the Users list.

Common configurations

Apply these configurations to each project that the user can open. Set the All row first, then change the rows listed below it.

Read-only reviewer

Views everything. Changes nothing. Wren answers questions but does not build.

Conversation analyst

Reviews conversations and builds dashboards. Cannot see build areas.
The Conversations row does not set its items, so set each item one by one.

PII-restricted analyst

Same as the conversation analyst, but cannot see unmasked personal data or download recordings. Use this configuration for external teams or for users who do not need personal data.

Knowledge editor

Edits FAQs, sources, and variants. Reads everything else.

Builder

Builds and tests the agent. Reads the Deployments page but does not manage environments there.

Operations manager

Deploys, manages real-time configuration, and owns analytics. Does not change agent logic.

User management

Overview of roles, projects, and permission levels.

Add users

Add users, assign a role, and set project permissions.

Manage users

Edit, delete, and export users. Re-send invitations.
Last modified on September 9, 2026