Glob.AI OS uses a role-based access control model that determines what users can view, build, and manage across the platform. Roles are assigned at different scopes: platform, Organization, Project, or usage. The permissions available to a user depend on the role assigned to their account in each scope.
| Role |
Scope |
Purpose |
| SuperAdmin (System Administrator) |
Platform |
Has full control over the platform at all levels, including global Organization, security, and system configuration. |
| Organization Administrator (Organization Member) |
Organization |
Manages users, roles, permissions, and configurations within an Organization. Also creates Projects and administers memberships. |
| Publishing Administrator |
Organization |
Publishes AI solutions within an Organization. |
| Project Administrator |
Project |
Manages a specific Project, including member lists, roles, and all Project configuration options. |
| Project Member |
Project |
Builds and uses AI solutions within a specific Project. |
| Consumer |
Usage (cross-cutting) |
Discovers and runs existing AI solutions through the Frontend. Consumers are users assigned Frontend roles, which grant access to the Discover section. They cannot create or modify AI solutions. To grant Frontend access to users from a specific domain, see Allowing Frontend Access for Users from Specific Domains. |
Builder is a user, not a platform role. It refers to any user responsible for creating AI solutions, typically a Project Member, Project Administrator, or Organization Administrator.
The matrix below lists permissions by area and indicates which roles have access.
| Permission |
SuperAdmin |
Org Admin |
Publishing Admin |
Project Admin |
Project Member |
Consumer |
| Manage AI Models |
✓ |
✓ |
— |
— |
— |
— |
| Permission |
SuperAdmin |
Org Admin |
Publishing Admin |
Project Admin |
Project Member |
Consumer |
| Create / edit Integration Agent Tools |
✓ |
✓ |
— |
✓ |
— |
— |