Access to one resource
A resource's page in your tenant lists the users and groups that may use or manage that one resource. A grant covers that resource only. It changes nothing else in the tenant.
Where to find it
Open the resource in your tenant and scroll down its page:
| Resource | Sections |
|---|---|
| Preset Agents → an agent | Administrators, Users |
| Models → a connected external model | Administrators, Users |
| MCP Servers → a server | Administrators |
| RAG endpoints → an endpoint → the Access tab | Administrators, Viewers |
An external model shows these sections only for a connection your own tenant owns, and only to a tenant administrator.
Pages under Manage platform have no such sections. There you share the resource with whole tenants instead.
What each section means
- Administrators — manage the resource: edit it and delete it. For an agent, also share it. For a RAG endpoint, also start it, stop it, and manage its data sources. An administrator can use the resource too.
- Users — use the resource and nothing more: chat with the agent, or send requests to the model.
- Viewers — read a RAG endpoint's configuration and data sources, without changing anything.
Add a user or a group
- Select Add administrator, Add user or Add viewer.
- Search by name or email. The search covers the members and the groups of your tenant.
- Tick everyone you want to add, then select Add.
Adding a group gives the access to every member of that group — the simplest way to cover a whole team.
If a section reads Adding people needs tenant administration access, you can see and remove the entries that are already there, but you cannot add new ones. Ask a tenant administrator to add the person for you.
Remove access
Each row shows the name and whether the entry is a User or a Group. Select the remove button on the row and confirm. Access the same person holds through the tenant is not affected — only the entry you removed.