Roles
Admin
Admins have full workspace administration access. They can configure workspace settings, manage members and groups, and control permissions. Admins always retain access to capabilities set to Admin only. By default, Admins can:- Manage billing and subscriptions
- Manage security settings, user access, identity verification, and provisioning
- Configure governance permissions
- Enable or disable Frames for the workspace
- Enable or disable audit logs
Manager
Managers are delegated workspace administrators. They can:- Open the Admin area
- Invite and remove members
- Change the roles of non-admin members
- Assign the Manager and Member roles
- View workspace analytics and usage page
Member
Members use Dust according to their seat, group memberships, resource access, and granted permissions. Members do not have administrative access by default. Admins can grant Members additional permissions through groups.Groups and permissions
Dust supports two types of groups:- Provisioned groups, synchronized from your identity provider through SCIM
- Manual groups, created and managed in Dust
Permission matrix
The following permissions are available in the workspace governance settings.
Publishing agents and publishing skills are separate permissions. You can grant them independently. Publishing skills is restricted to Admins by default. Admins can configure the permission for groups when broader access is needed.
Workspace governance settings
Workspace settings and permission controls are managed under Settings & Governance. Billing and security are permissions, not separate roles. Admins receive access by default. Admins can delegate either permission to selected groups without changing those members’ workspace roles.The Builder role
The Builder role is being replaced by separate permissions for creating and publishing agents and skills. During the transition, workspaces that used the Builder role receive a Builders group. Existing builders are added to that group, which preserves their agent and skill creation access without preserving a broad Builder role. API keys using thebuilder role receive the legacy Builders group instead. The API key role is removed in the end state.
Admins can move those permissions to other manual or provisioned groups as their workspace model evolves.
How access is determined
A person’s effective access combines:- Their workspace role
- The permissions granted to their groups
- Their access to specific resources, such as spaces, agents, skills, and other workspace content