Access to one resource
A resource's page in your tenant lists the users, the groups and the tenant itself that may use or manage that one resource. A grant covers that resource only. It changes nothing else in the tenant.
Where to find it
Open the resource in your tenant. The sections sit on the Users tab, or further down the page:
| Resource | Sections |
|---|---|
| Preset Agents → an agent → the Users tab | Administrators, Users |
| Models → a connected external model → the Users tab | Administrators, Users |
| MCP Servers → a server → the Users tab | Administrators, Users |
| RAG endpoints → an endpoint → the Users tab | Administrators, Users |
An external model shows these sections only for a connection your own tenant owns, and only to a tenant administrator.
Pages under Manage platform have no such sections. There you share the resource with whole tenants instead.
What each section means
- Administrators — manage the resource: edit it and delete it. For an agent, also share it. For a RAG endpoint, also start it, stop it, and manage its data sources. An administrator can use the resource too.
- Users — use the resource and nothing more: chat with the agent, run inference with the model, call the server's tools, or read a RAG endpoint's configuration and data sources.
Add a user or a group
- Select Add administrator or Add user.
- Search by name or email. The search covers the members and the groups of your tenant.
- Tick everyone you want to add, then select Add.
Adding a group gives the access to every member of that group — the simplest way to cover a whole team.
Give access to everyone in your tenant
Above the sections is Everyone in this tenant. Turn Share with everyone in this tenant on, select Save, and every member of your tenant may use the resource — including people who join later. Turn it off again to take that access away.
The switch names your own tenant only. To let another tenant use a platform resource, share the resource with that tenant from the Manage platform pages instead.
Remove access
Each row shows the name and whether the entry is a User, a Group or a Tenant. Select the remove button on the row and confirm. Access the same person holds another way is not affected — only the entry you removed. Removing a tenant entry takes the access away from everyone who had it through that entry alone.