Learn how Cotonity's role-based access control works for agents — who can create, edit, run, or delete an agent, and how to set data-access scopes.
Workspace roles overview
Every member of a Cotonity workspace is assigned one of four roles: Viewer, Editor, Developer, or Admin. Viewers can see agent configurations and logs but cannot make changes. Editors can update agent prompts and workflow nodes but cannot create new agents or manage integrations. Developers have full create/edit/delete rights over agents, workflows, and integrations but cannot manage billing or user accounts. Admins have unrestricted access to everything in the workspace, including billing, team management, and security policies. Roles are assigned per workspace, so a user can be an Admin in one workspace and a Viewer in another.
Agent-level permissions
Beyond workspace roles, each individual agent has its own permission settings accessible under the agent's Settings tab. You can designate specific team members as Agent Owners — these users receive run-failure alerts for that agent regardless of their notification preferences. You can also restrict which roles are allowed to run an agent: for example, marking a production-facing customer support agent as "Developers and Admins only" prevents Editors from triggering accidental test runs against live data. Agent-level permissions are layered on top of workspace roles, so a user needs both the appropriate workspace role and the agent permission to perform an action.
Data access scopes
When you attach an integration to an agent — for example, a HubSpot connection — you must also define the data access scope for that agent. Click the integration tile in the agent's Connect step and select a scope: Read Only, Read/Write, or Full Access. Read Only prevents the agent from creating or modifying CRM records even if the underlying integration token allows it. This principle of least privilege reduces the blast radius if an agent behaves unexpectedly. You can audit which agents have which scopes at any time from Integrations → [Integration Name] → Agent Access.
Audit log for permission changes
Every permission change in Cotonity — role assignments, agent scope changes, integration authorizations — is recorded in the Audit Log under Settings → Audit Log. Each entry shows the actor (who made the change), the target (what was changed), the old and new values, and a timestamp with timezone. Audit logs are immutable and retained for 12 months on Pro plans and 24 months on Enterprise plans. You can export the audit log as a CSV or JSON file for compliance reporting. If you notice an unexpected change, click the entry to see the full context and use the "Flag for Review" button to notify your Admins.