> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gc.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> Understand how organization roles, access tiers, and sharing determine what each member can do

Access in a GC AI organization depends on four controls:

1. **Organization role** determines who can manage the organization.
2. **Access tier** determines which product permissions a member is eligible to use.
3. **Product roles** grant specific permissions.
4. **Resource sharing** determines which private content the member can open.

All four controls apply. A role cannot grant a permission that the member's access tier does not support, and a product permission does not reveal private content that has not been shared with the member.

## Organization roles

Every organization member is either an **Admin** or **Member**.

### Admin

Admins can:

* Invite new members to the organization
* Remove members from the organization
* Manage access tiers and product roles
* Update organization details
* Enable or disable public chat sharing for the organization (when disabled, users see a notice and sharing actions are blocked)
* Enable or disable Google Drive import for all members
* Manage Agent Connector policies for the organization
* Opt in to Claude Fable 5 and opt out of AI model providers
* Manage web search approval settings
* Manage billing and seat settings

Admin grants organization management access. It does not grant product permissions by itself.

### Member

Members cannot administer the organization or manage organization membership. Their product access comes from their access tier, assigned roles, and shared resources.

Both Admins and Members can connect their own accounts under [Agent Connectors](/guides/organizations/agent-connectors), subject to the organization's connector policy.

## Product roles

Product roles collect permissions that you can assign to members. Open **Settings → People → Roles** to review or create them.

### Built-in roles

* **Standard access** grants GC AI's standard product permissions. Members with a Legal seat or active trial receive all of them; a Stakeholder receives every [Stakeholder-eligible permission](/docs/organizations/stakeholder-seats#available-permissions).
* **Admin** grants organization management access and no product permissions.

GC AI manages built-in roles, so you can review but not edit them.

### Custom roles

Organization admins can create custom roles with the exact product permissions a team needs. You can assign a role directly to a member or to a user group. A member receives the combined permissions from every direct and group role.

Each permission shows which access tiers can use it, and **View permissions** in a member's roles menu lists which permissions are eligible for that member's access. Assigning a broader role does not expand the member's access tier. For example, a [Stakeholder seat](/docs/organizations/stakeholder-seats) cannot use Main Chat or project permissions even if an assigned role contains them.

Deleting a custom role removes its assignments. It does not delete members, groups, or content.

<Note>
  Your organization may need access to custom roles and Stakeholder seats. Contact your account team if **Settings → People → Roles** does not appear.
</Note>

## Access tiers

Access tiers set the maximum permissions a role can activate:

| Access tier | Permission eligibility |
| - | - |
| **Legal seat** | Can use any assigned product permission |
| **Trial access** | Can use any assigned product permission while the trial is active |
| **Stakeholder seat** | Can use selected Contract Intelligence permissions |
| **View only** | Keeps limited read access where permitted |

See [Stakeholder seats](/docs/organizations/stakeholder-seats) for the current permission list and organization-scoped behavior.

## How access combines

When a member opens a resource, GC AI checks:

1. Do the member's roles or View grants provide the required permission?
2. Does the member's access tier support that permission?
3. Can the member access this resource through a direct share, group share, or organization-wide setting?

The member gets access only when each required check passes.

A direct or group View grant provides the **Access shared Vaults and Views** permission for that content. The member does not need a separate product role for the shared View.

## Agent Connector access

A connector has three layers:

1. **Enabled by the organization**
2. **Connected by the member**
3. **Tool permissions allowed by the member**

The three layers determine whether GC AI can use a connector tool. It must be enabled by the organization, connected by an organization member, and allowed by that member's tool permissions.

For most connectors, organization admins control whether access is **Disabled**, **Read-only**, or **Full access** for all members or specific members in **Settings → Policies → Connector policies**. Only an organization admin can set a per-member exception.

<Note>
  Agent Connectors and Document Storage use separate access controls, although they may share the same member account connection.
</Note>

See [Agent Connectors](/guides/organizations/agent-connectors) for setup steps, default behavior, and policy details.

## Content privacy

By default, new content in GC AI is private:

* Individual chats are only visible to their creator, unless you share them or add them to a shared project
* Skills are private unless shared
* Company Profiles can be managed privately
* Content sharing requires an explicit action, including setting a project to Organization visibility

## Sharing controls

Users can control sharing through:

* Individual sharing with specific members
* Sharing with user groups
* Organization-wide sharing options
* Granular permission settings
* Revocable access controls

Access granted directly and through user groups is combined. When several grants apply, GC AI uses the highest access level. Group roles control group management and do not change access to shared resources.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.