Access Control

Action reference

Every action MagOneAI can authorize, what it allows, and the levels a grant for it can attach to

How to read this page

An action is one thing a person can do. A grant names an action, a level, and a target at that level.

The Can be granted at column records where it makes sense to author a grant on that action, narrowest first.

There are six real grant levels:

LevelA grant at this level is about
selfThe person's own data
usecaseOne use case
projectOne project
appOne app surface
orgOne organization
platformThe whole deployment

Two things about this column are worth knowing before you read it as a rule.

org and platform are always grantable, on every action, whether or not the row names them. A decision carrying an organization always considers an org token and a platform token, so a grant written at either level genuinely decides.

This is what lets Organization Owner hold the whole project ladder at org level, which is how an owner reaches every project.

Some rows name a resource, not a level. kb.view reads project, kb, and agent.run reads project, agent. There is no kb or agent grant level. Those entries say what the action is about; the levels you can actually grant at are the six in the table above, plus org and platform.

Reading this column as the set the engine evaluates is a known trap, and it is a different question from where a grant may be written.

Some actions list more than one real level, for example project, usecase. Those can be granted broadly or narrowly, and the narrow form is what lets you say "this one use case".

Remember that a wildcard target narrows what someone may do where they already are, while an explicit target establishes access to that one object. See wildcard and explicit targets.

Actions are fixed. You cannot create, rename or delete one. You bundle them into roles.

There are 128 actions across 26 modules.

Actions by module

Account and session

ActionWhat it allowsCan be granted at
account.manage.selfMy own account: profile, password, MFA, SSO linkself
app.openOpen Studio / Hub / Superadminapp
org.enterOrg switcher / select-orgorg
permission.view.selfMy own effective permissionsself
search.globalGlobal search boxorg

Organizations

ActionWhat it allowsCan be granted at
branding.manageBranding / whitelabelorg
invitation.view.selfMy pending invitationsself
member.inviteInvite / add memberorg
member.removeRemove memberorg
member.role.manageChange member roleorg
member.viewMembers screenorg
mfa.policy.manageMFA policyorg
orgsettings.manageOrg settingsorg
sso.manageSSO providersorg
sso.viewSee which SSO providers are configuredorg

Projects

ActionWhat it allowsCan be granted at
project.createCreate projectorg
project.deleteDelete projectproject
project.editProject settingsproject
project.listProjects listorg
project.members.manageMembers tab, add / change roleproject
project.viewOpen a projectproject

Access control

ActionWhat it allowsCan be granted at
magauth.mode.manageEnforcement mode toggleorg
magauth.pap.manageAccess-control grid, grant / revokeorg, platform
magauth.request.createRequest access to a surfaceself
magauth.request.decideAccess requests approve / denyorg

Use cases

ActionWhat it allowsCan be granted at
usecase.createCreate use caseproject
usecase.deleteDelete use caseproject, usecase
usecase.docs.viewDocumentation view / exportproject, usecase
usecase.editCanvas open + saveproject, usecase
usecase.exportExport workflow JSON (prompts included)project, usecase
usecase.generateAutobuild / generateproject
usecase.header.previewCode-activity header previewself
usecase.importImport workflowproject
usecase.listUse-cases listproject
usecase.publishPublish / version snapshotproject, usecase
usecase.runRun / Execute CTAproject, usecase
usecase.unpublishUnpublish / withdraw a published versionproject, usecase
usecase.validateValidate workflow / inputproject, usecase
usecase.viewOpen use-case detailproject, usecase

Executions

ActionWhat it allowsCan be granted at
execution.access.requestRequest access to a redacted runproject
execution.cancelCancel a runproject, usecase
execution.children.viewChild executions drill-downproject, usecase
execution.confidential.viewRun that touched a personal connector or docorg
execution.debugActivity timeline / debug viewproject, usecase
execution.exportExport executions to Excelproject, usecase
execution.listHistory listproject, usecase
execution.payload.readInputs / outputs / variables payloadproject, usecase
execution.shareShare my run with a person or the projectself
execution.stats.viewStats tiles / countsproject
execution.view.anyOpen anyone else's runproject
execution.view.ownOpen a run I startedproject, usecase

Agents

ActionWhat it allowsCan be granted at
agent.editCreate / edit agent persona + promptproject, agent
agent.prompt.previewPreview / enhance promptproject, agent
agent.runRun a single agent ad hocproject, agent
agent.viewAgents list / detailproject

Knowledge bases

ActionWhat it allowsCan be granted at
kb.createCreate KBproject
kb.deleteDelete KB / documentproject, kb
kb.listKB listproject
kb.scheduleSchedule recurring URL crawlproject, kb
kb.searchSearch inside KBproject, kb
kb.syncURL crawl / SharePoint resyncproject, kb
kb.uploadUpload documentproject, kb
kb.viewOpen KB, browse documentsproject, kb

Tools and MCP

ActionWhat it allowsCan be granted at
credential.connect.selfConnect my personal account (Outlook, Teams)org
credential.manage.orgProject / org connectionsorg
credential.manage.platformPlatform credentialsplatform
credential.manage.projectProject connections create / edit / removeproject
credential.view.orgSee org connections (tool picker)org
mcpserver.manageExternal MCP serversorg
tool.invokeTool invoked at runtimeproject, usecase, tool
tool.viewTools catalog (project / org)project, org

Models

ActionWhat it allowsCan be granted at
llmaccess.managePer-project model accessproject
llmconfig.manageCreate / edit LLM config (API keys)org
llmconfig.viewLLM configs listorg

Chat

ActionWhat it allowsCan be granted at
chat.attachAttach file to a messageproject, usecase
chat.listConversations list (Studio)project
chat.manageRename / delete conversationproject, usecase
chat.model.selectModel pickerproject, usecase
chat.sendSend messageproject, usecase
chat.startStart a conversationproject, usecase
chat.view.anyRead anyone else's conversationproject
chat.view.ownRead my own conversationproject, usecase

Files

ActionWhat it allowsCan be granted at
artifact.viewGenerated artifact downloadproject
file.deleteDelete fileproject
file.download.anyDownload anyone's fileproject
file.download.ownDownload a file I uploadedproject
file.uploadUpload file (START node / chat)project

Human tasks

ActionWhat it allowsCan be granted at
humantask.respondRespond to a human taskself
humantask.view.anySee anyone's tasksproject
humantask.view.ownMy tasks inboxself

Schedules

ActionWhat it allowsCan be granted at
schedule.manageCreate / edit / pause / resumeproject, usecase
schedule.triggerTrigger nowproject, usecase
schedule.viewSchedules listproject, usecase

Webhooks

ActionWhat it allowsCan be granted at
inbound_webhook.manageInbound webhooks create / rotate / editproject, usecase
inbound_webhook.viewInbound webhooks list + delivery logproject, usecase
webhook.manageWebhooks create / rotate / editproject, usecase
webhook.viewWebhooks list + delivery logproject, usecase

Usage and quotas

ActionWhat it allowsCan be granted at
quota.manageToken quotas / limitsorg
quota.request.approveApprove / reject limit requestorg
quota.request.selfAsk for a higher token limit, and see my own requestsself
usage.org.viewOrg usage + cost breakdownorg
usage.self.viewMy usageself

Analytics

ActionWhat it allowsCan be granted at
analytics.org.viewOrg analytics + exportorg
analytics.platform.viewPlatform-wide dashboardplatform
analytics.project.viewProject analyticsproject
analytics.usecase.viewUse-case analyticsproject, usecase

Secrets

ActionWhat it allowsCan be granted at
secret.manage.orgOrg vault read / writeorg
secret.manage.projectProject managed secretsproject
secret.manage.selfMy own vault entriesself

API keys

ActionWhat it allowsCan be granted at
apikey.manageCreate / revoke API keyproject

Notifications

ActionWhat it allowsCan be granted at
notification.viewNotificationsself

Templates store

ActionWhat it allowsCan be granted at
store.browseBrowse template store: listings, categories, detail, snapshotplatform
store.installPreview / install a store template into a projectproject
store.managePublish / edit / remove store listings, upload store assetsplatform

Test cases

ActionWhat it allowsCan be granted at
testcase.manageCreate / edit / delete test casesproject, usecase
testcase.runRun test casesproject, usecase
testcase.viewTest cases list / detail / reportproject, usecase

AI helper tasks

ActionWhat it allowsCan be granted at
ai_task.viewPoll async AI helper job status (enhance / docs / test cases)project

Feedback

ActionWhat it allowsCan be granted at
feedback.submitRate, re-rate or un-rate a runproject
feedback.viewFeedback listproject

Support

ActionWhat it allowsCan be granted at
support.self.manageSubmit and track your own support ticketsself

Platform administration

ActionWhat it allowsCan be granted at
audit.viewAudit log readplatform
marketplace.manageMarketplace plans / subscriptionsplatform
org.manageOrgs CRUDplatform
orggroup.manageOrg groupsplatform
platform.settings.managePlatform settings / prompts / emailplatform
support.manageSupport queriesplatform
user.manageUsers CRUD / bulk importplatform

Next steps

MagOneAI© 2026 Magure, Inc.

On this page