Organization & Member Management
The three-tier structure of organizations, roles, and members, and the three things contained in a role—feature permissions, creation permissions, and resource assignments. Read this page before setti
What Is Organization and Member Management?
MaiAgent's organization and member management works like setting up a "digital office" for your company: first create an organization for your company, add departments (roles), decide what each department can use, and then add colleagues to the appropriate departments.
This design is based on RBAC (Role-Based Access Control): permissions are assigned to roles, not directly to individuals.
Three-Tier Structure: Organization → Role → Member

Organization
Your company
The top-level management unit. Members, roles, AI assistants, and knowledge bases all belong to an organization. Organizations are completely isolated from one another.
Role
Department or position
A container for permissions and resources. A member can belong to multiple roles at the same time and receives the combined permissions of all those roles.
Member
Employee
A user in the organization. Members have no permissions of their own; all permissions come from the roles to which they belong.
What a Role Contains
Many people think of permissions in terms of "create/read/update/delete," but the platform organizes them differently. A role contains three elements, and all three apply together:

Feature permissions
Which items appear in the left sidebar. These permissions only control visibility; they do not distinguish between read, edit, and delete access.
The Role Permissions tab for the role. Selecting a parent permission automatically includes all child permissions, or you can select only specific child permissions.
Creation permissions
Whether members can create assistants, knowledge bases, databases, and conversation platforms.
The "Allow creating" checkbox at the top of each resource assignment tab.
Resource assignments
Which assistants and knowledge bases members can access. Each item has separate read, edit, and delete controls.
The role's Assign AI Assistants, Assign Knowledge Bases, and other resource tabs.
Resources That Can Be Assigned to Roles
The tabs on the role editing page show the resources you can assign:
AI Assistants, Knowledge Bases, Databases, and Conversation Platforms: Each includes read, edit, and delete permissions
Tools, Skills, and Agent UI Tools: Capabilities that members of the role can attach to assistants
MaiGPT Access: Whether members of the role can use MaiGPT
Credit Quota: The usage limit for the role. See Credit Billing for details

Core Concepts
Three Types of Roles
Owner
The organization creator or designated administrators
Bypasses all permission checks and can view and modify every resource in the organization. An organization can have multiple owners.
Default Role
All members, who are assigned automatically
Any permission it grants is available company-wide, and any assistant assigned to it is visible to everyone. We recommend granting only minimum permissions and assigning no resources.
Custom Role
Assigned members
Created by department or position. Custom roles can be duplicated and assigned in batches.

Two Types of Members
Owner
Everything. Owners can manage organization settings, roles, and members.
Regular Member
The permissions of the default role, plus the permissions from every role assigned to the member.
Visibility is based only on roles, not on who created a resource. Members of every role assigned to an assistant can see it. The platform does not grant additional permissions just because "I created it." The only way to make an assistant visible solely to its creator is to create one role per person. See the Role and Permission Planning Guide for instructions.
Recommended Setup Order
Create an organization: See Organization Management
Connect a sign-in method: To use company accounts, configure Third-Party Sign-In (SSO) first. Member email addresses must match their SSO accounts
Restrict the default role: Grant only minimum permissions and do not assign any resources
Create roles: Create roles by department or position, then select feature and creation permissions. See Role Permission Management
Assign resources: Assign assistants, knowledge bases, and other resources to roles, then configure read, edit, and delete access. See Role Resource Access Permissions
Add members and assign roles: See Member Management. Use batch import for larger teams
Test with a regular member account: Owners bypass all permission checks, so an owner account does not show the actual member experience
Related Pages
Organization Management: Create, switch, and manage organizations
Roles and Permissions: Role permission management, resource access permissions, member filters, differences between roles and contacts, and the role and permission planning guide
Member Management: Add and remove members and assign roles
Third-Party Sign-In (SSO) and Identity Sync (LDAP): Sign in with company accounts and synchronize members
Last updated
Was this helpful?
