Permission groups decide which models a set of users can access and apply a rate multiplier to their billing. Use them to package models by team, plan, or provider.
Where to find it#
Open the admin console and select Permission Groups. The list shows each group's name, description, rate multiplier, model count, and covered users.
The table is searchable by name or description. Click a row to edit the group. The Default badge marks the built-in group that covers all users.
| Column | Meaning |
|---|---|
| Name | Group name. The default group is marked Default. |
| Description | Free-text note about the group. |
| Rate multiplier | Billing unit price multiplier. 1 means no change. |
| Models | Total model count, with a manual · automatic breakdown. |
| Covered users | Total user count, with a manual · subscription breakdown. The default group shows All users. |
Create a permission group#
- Click Create permission group.
- Fill in Name (required), Description, and Rate multiplier.
- Click Create.
New groups start with no manual models, no automatic rules, and no manual members. Configure access after creation. The rate multiplier must be greater than 0; an empty or invalid value is stored as 1.
Edit a permission group#
Click a row to open the edit sheet. It has two sections:
- Basics: name, description, and rate multiplier.
- Access scope: Accessible models and Member users, each with a Configure button.
Click Save to write the name, description, rate multiplier, models, rules, and manual members together.
Configure accessible models#
Open Configure accessible models. The dialog combines manual selection with automatic rules.
- Under Automatic rules, choose a rule type and value, then click Add.
- Under Manual rules, search models and select the ones to include.
- Click Done to close the picker, then Save on the group sheet.
Automatic rules accept one type at a time:
| Rule | Effect |
|---|---|
| Auto-include all | Every model joins the group. This replaces all other rules. |
| Vendor | Every model from the selected vendor joins the group. |
| Protocol | Every model that uses the selected protocol joins the group. |
| Upstream | Every model with a source on the selected upstream joins the group. |
A rule is skipped if it duplicates an existing rule, and value rules cannot be added while Auto-include all is present. Remove a rule with the × on its badge.
The manual model list supports search plus Upstreams, Vendor, and Protocols filters. Select all adds every model that matches the current search and filters, not only the visible page; Clear removes the manual selection.
Configure manual members#
Open Configure manual members to add users directly to the group. Manual membership is independent of subscriptions.
- Search by username, name, or email.
- Filter by Subscription (all, active subscription, free or none) and Identity source.
- Use Select all for the whole filtered result set, or Clear to remove manual members.
The default group cannot configure manual members. It always covers all users and shows All users · {count}. Other groups show a manual · subscription summary: manual members plus users whose active subscription plan references the group.
Delete a permission group#
Click the trash button on a row. The confirmation lists what will be removed: manual models, automatic rules, and manual members.
- The default group cannot be deleted.
- A group referenced by a billing plan cannot be deleted.
- Deleting a group does not delete the platform models themselves; it removes their membership in this group.
A model that matches no permission group is hidden from users. Check the group list after changing rules so important models stay reachable.
Troubleshooting#
| What you see | What to check |
|---|---|
| Failed to load permission groups | Refresh the page. If the session expired, sign in again. |
| Failed to save | Check the name and rate multiplier, then save again. |
| Cannot delete the default permission group | The default group is built in. Edit its access instead of deleting it. |
| A model is missing for users | The model matches no group, is disabled, or its sources are unavailable. |
| Members do not see a model | The model is not in any group that covers those users, or automatic rules do not match it. |