Roles
Create and manage roles to control what users can do within your organisation
Roles define what users are allowed to do in DeutschlandGPT. Each user can hold one or more roles. Permissions are additive: if any assigned role grants a permission, the user has it. Assign roles to users under Users.
System roles
Two roles exist by default and cannot be deleted:
| Role | Description |
|---|---|
| Admin | Full access to all organisation settings. This role cannot be edited; it always carries every permission. |
| User | The default role for regular members. Permissions are configurable. |
Custom roles
Click Create role to define a role with any combination of permissions. Custom roles can be deleted; system roles cannot.
Each role has:
- Name: internal identifier
- Display name: shown in the UI
- Description: optional context for administrators
- Permissions: checkbox-based permission set (see below)
The bottom of each role's edit page lists all users currently assigned to that role.
Permission reference
Administrative permissions
| Permission | What it allows |
|---|---|
| Manage AI model selection | Restrict or configure which AI models are available to the organisation |
| Adjust organisation settings | Edit general organisation settings |
| Manage billing | View and manage organisation billing and licences |
| View audit log | Access the audit log |
Agents
| Permission | What it allows |
|---|---|
| Agents: create | Create new agents |
| Agents: delete | Delete agents |
| Agents: read | View agents |
| Agents: update | Edit existing agents |
| Agents: use | Start and run agents |
Desktop app
The desktop app reads and writes local files and shared project folders. These permissions let you hand it only to employees who have been briefed on it. Without "Use desktop app" even signing in to the app is impossible; the other two require it.
| Permission | What it allows |
|---|---|
| Use desktop app | Sign in to the desktop app and use chat inside it |
| Use CoWork in the desktop app | "CoWork", including access to shared local folders |
| Use Code in the desktop app | "Code", including access to shared project folders and running commands |
Chat permissions
| Permission | What it allows |
|---|---|
| Share chats | Share a chat via a link |
| Create documents | Generate files (PDFs, Word, etc.) from chats |
| Upload documents | Upload files in a chat |
| Manage integrations | Connect and disconnect personal integrations |
| Use web search | Use the web search tool in chats |
| Select AI models | Choose which model to use per conversation |
| Use voice input | Use speech-to-text input |
Custom AI Applications
| Permission | What it allows |
|---|---|
| Create applications | Build new Custom AI Applications |
| Use applications | Start chats using existing applications |
| Share applications | Share applications with other users or groups |
| Create templates | Save an own application as a template for the rest of the organisation |
| View templates | Open the template gallery and browse the templates offered there |
The last two are deliberately separate from "Use applications": you can let a role browse the curated templates without letting it build its own applications — or hide the gallery from a role that does use applications. Starting a chat from a template additionally requires "Use applications"; turning one into an own application additionally requires "Create applications".
Document folders
| Permission | What it allows |
|---|---|
| Create folders | Create new document folders |
| Use folders | Access and search document folders in chats |
| Share folders | Share folders with other users or groups |
Glossary
| Permission | What it allows |
|---|---|
| View glossary entries | Read entries in the organisation glossary |
| Edit glossary entries | Update existing entries |
| Create glossary entries | Add new entries |
| Delete glossary entries | Remove entries |
Groups
| Permission | What it allows |
|---|---|
| View groups | See the groups list |
| Edit groups | Update group name, description, members |
| Create groups | Create new groups |
| Delete groups | Delete custom groups |
Platform API
| Permission | What it allows |
|---|---|
| Use Platform API | Generate API keys and make API calls |
| Manage platform billing | View and manage API billing |
Projects
| Permission | What it allows |
|---|---|
| Create projects | Create new projects |
| Use projects | Access and work within projects |
| Share projects | Share projects with other users |
Roles
| Permission | What it allows |
|---|---|
| View roles | See the roles list |
| Edit roles | Modify existing custom roles |
| Create roles | Create new roles |
| Delete roles | Delete custom roles |
Usage statistics
| Permission | What it allows |
|---|---|
| View usage statistics | Access the usage dashboard |
Users
| Permission | What it allows |
|---|---|
| View users | See the user list |
| Edit users | Update user name and roles |
| Create users | Invite new users |
| Delete users | Remove users from the organisation |
Workflows
| Permission | What it allows |
|---|---|
| Share workflows | Share workflows with other users |
| View workflows | See the workflows list |
| Run workflows | Execute existing workflows |
| Edit workflows | Modify existing workflows |
| Create workflows | Build new workflows |
| Delete workflows | Delete workflows |