Skip to main content

Roles — Understanding Permissions in TraptureIQ

Every user in your workspace is assigned exactly one role. The role determines which platform sections and actions the user can access. This page provides a complete breakdown of both roles.


Tenant Admin — Full Control

The Tenant Admin is the "power user" who manages the workspace. You become a Tenant Admin automatically when you create a workspace, and you can promote other users to Admin.

What Tenant Admins Can Do:

CategoryCapabilities
Agent ManagementRegister, edit, deactivate, and delete agents
User ManagementInvite users, change roles, disable/delete accounts, configure section access
SecurityEnable/disable AgentGuard, configure firewalls, monitor safety events
BillingManage subscription, view payment history, generate API keys
All Platform SectionsAccess every module without restriction

Admin-Only Sections (only visible to Admins — cannot be granted to Tenant Users):

SectionWhat It Does
Admin & Access ManagementAgent dashboard, user management, agent access control, permission matrix, settings
AnalyticsUsage dashboards — request volume, latency, error rates, tool usage
Cost ControlToken usage and LLM cost tracking per agent/user/session
AgentGuardAI safety guardrails — firewalls, PII detection, content safety monitoring
IntelligenceAgent reasoning insights and behavior patterns

Tenant User — Configurable Access

The standard role for everyday use. Tenant Users can only access sections that a Tenant Admin has explicitly enabled for them.

Configurable Sections (enabled/disabled per user by an Admin — all enabled by default):

SectionWhat It Does
AgentsBrowse and chat with assigned agents
TracesView agent execution traces and user journeys
LogsView system and agent logs
EvalRun custom, security, and load test evaluations
SessionView chat session history and statistics
PromptsCreate and manage versioned prompt templates
MCP DebugDebug MCP integrations and test MCP tools

Always-Accessible Section (visible to all users, no configuration needed):

SectionWhat It Does
AnalyserToken counting and cost estimation tool

Admin-Only Sections (Tenant Users cannot access these regardless of configuration):

SectionWhat It Does
Admin & Access ManagementUser management, settings, and permissions
AnalyticsUsage and performance dashboards
Cost ControlToken cost monitoring
AgentGuardAI safety guardrails and monitoring
IntelligenceAgent reasoning insights and behavior patterns

Role Comparison Table

CapabilityTenant AdminTenant User
Chat with assigned agentsYesYes
View own session historyYesYes
Use AnalyserYesYes
Access configurable sections (Agents, Traces, Logs, Eval, Session, Prompts, MCP Debug)AllPer-user toggle
Access admin-only sections (Analytics, Cost Control, AgentGuard, Intelligence)YesNo
Register/edit/delete agentsYesNo
Invite/manage usersYesNo
Change user rolesYesNo
Configure billing & subscriptionYesNo
Set section access for usersYesNo
Configure per-agent user accessYesNo
Manage API keysYesNo
Enable/disable AgentGuardYesNo
Configure firewall rulesYesNo

Role Comparison — Replace with actual screenshot


Choosing the Right Role

ScenarioRecommended Role
Team lead who manages agents and usersTenant Admin
Developer who needs to debug and test agentsTenant User with Traces, Logs, Eval, MCP Debug enabled
Business user who only chats with agentsTenant User with Agents and Session enabled
Security engineer who monitors safetyTenant Admin (needs AgentGuard access)
External contractor with limited accessTenant User with minimal sections + specific agent access
Data analyst reviewing usage patternsTenant Admin (needs Analytics and Cost Control)

Tips for Beginners

  • Every workspace needs at least one Tenant Admin — without one, no one can manage users or agents.
  • Start restrictive, then open up — Give new users the Tenant User role with minimal sections. Add access as they need it.
  • Admin is powerful — Admins can manage billing, delete users, and access all data. Only promote users you trust.
  • Role changes are instant — When you change someone's role, the effect is immediate on their next page load.