SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Identity and access

Roles and scopes

Every permission is a scope; roles are fixed sets of scopes, and keys carry a subset of their creator's.

How permissions work

A scope is a permission such as projects:write. Every request is checked for the scope it needs, in the organization it acts on:

  • People get the scopes of their role in each organization. They're worked out from the role in the access token, so a role change takes effect within 15 minutes.
  • Keys carry the scopes chosen when they were created, at most the creator's own (Keys).
  • Agents don't use scopes; what a device may do is decided when it's approved.

A request without the scope gets 403 with Missing scope <scope>.

Roles

RoleScopes
OwnerEvery scope except the platform ones. Owners can also invite owners.
AdminSame scopes as owners.
DeveloperEvery :read scope except audit:read, plus the developer writes marked in the table below.
ViewerEvery :read scope except audit:read, plus chat:use.

In the platform organization, owners and admins also get the platform: scopes. A few decisions use the role itself rather than a scope: inviting members, creating and deleting teams, and creating and revoking keys need an owner or admin.

Scopes

Generated from the platform's scope list. Checked by lists the API routes and MCP tools that require each scope; "Not checked yet" means a role grants it but nothing requires it today.

ScopeCoversOwnerAdminDeveloperViewerChecked by
platform:adminOrganizations, plans, platform stats and the platform audit log.Platform orgPlatform org10 API routes
platform:infraThe region and location registry.Platform orgPlatform org3 API routes
platform:analyticsTraffic across every customer deployment.Platform orgPlatform org2 API routes
org:readThe organization's settings page in Cloud.✓✓✓✓2 API routes, Cloud navigation
org:writeRenaming and deleting the organization; transferring projects (needed in both organizations).✓✓4 API routes
audit:readThe organization's audit log.✓✓3 API routes
members:readThe organization's members.✓✓✓✓1 API route
members:writeManaging the organization's members.✓✓Not checked yet
projects:readProjects and their settings.✓✓✓✓3 API routes
projects:writeCreating projects and changing their settings.✓✓✓7 API routes
deployments:readDeployments and their status.✓✓✓✓2 API routes
deployments:writeRedeploying, promoting and rolling back deployments.✓✓✓4 API routes
env:readEnvironment variables. Sensitive values are never returned.✓✓✓✓1 API route
env:writeAdding, changing and deleting environment variables.✓✓✓3 API routes
domains:readCustom domains and their status.✓✓✓✓3 API routes
domains:writeAdding, redirecting, moving and removing custom domains; connecting Cloudflare.✓✓✓8 API routes
resources:readDatabases and buckets.✓✓✓✓14 API routes
resources:writeCreating, linking and deleting databases and buckets.✓✓✓18 API routes
git:readReading repositories, cloning and fetching; reading and opening issues; commenting.✓✓✓✓50 API routes, Git over HTTPS: clone and fetch
git:writePushing; creating and deleting repositories; repository settings; opening and merging pull requests.✓✓✓16 API routes, Git over HTTPS: push
logs:readBuild and runtime logs.✓✓✓✓4 API routes
analytics:readTraffic analytics for the organization's deployments.✓✓✓✓1 API route
knowledge:readKnowledge pages and context entries.✓✓✓✓6 API routes, context_get, context_list, pages_list, page_get, page_search
knowledge:writeCreating and editing knowledge pages and context entries.✓✓✓4 API routes, context_put, context_delete, page_upsert
connectors:readConnectors, and their tools on the MCP server.✓✓✓✓2 API routes, connectors_list, connector tools
connectors:writeAdding, testing, changing and removing connectors.✓✓6 API routes
chat:useChat.✓✓✓✓Not checked yet
mcp:connectConnecting MCP clients.✓✓✓Not checked yet
agents:readAgents, their network requests and jobs.✓✓✓✓2 API routes, agent_job_get
agents:writeApproving and revoking agents, their network access, and exec jobs.✓✓4 API routes, agent_job_create, Approving an agent's login
agents:runQueueing agent jobs.✓✓✓3 API routes, agent_job_create, agent_job_cancel
mail:readReading and organizing mail in the mailboxes you're a member of.✓✓✓✓12 API routes
mail:sendSending mail and saving drafts from the mailboxes you're a member of.✓✓✓✓7 API routes
mail:adminMail domains, mailboxes, aliases, catch-all addresses and mail usage.✓✓13 API routes
calendar:readCalendars and events of the mailboxes you're a member of.✓✓✓✓4 API routes
calendar:writeCreating and changing calendars and events, answering invitations and importing events, in the mailboxes you're a member of.✓✓✓✓8 API routes
contacts:readAddress books and contacts of the mailboxes you're a member of.✓✓✓✓5 API routes
contacts:writeCreating, changing, importing and deleting contacts and address books in the mailboxes you're a member of.✓✓✓✓9 API routes