Access Control
Action reference Every action MagOneAI can authorize, what it allows, and the levels a grant for it can attach to
An action is one thing a person can do. A grant names an action, a level, and a target at that level.
The Can be granted at column records where it makes sense to author a grant on that action, narrowest first.
There are six real grant levels:
Level A grant at this level is about selfThe person's own data usecaseOne use case projectOne project appOne app surface orgOne organization platformThe whole deployment
Two things about this column are worth knowing before you read it as a rule.
org and platform are always grantable , on every action, whether or not the row names them. A decision carrying an organization always considers an org token and a platform token, so a grant written at either level genuinely decides.
This is what lets Organization Owner hold the whole project ladder at org level, which is how an owner reaches every project.
Some rows name a resource, not a level. kb.view reads project, kb, and agent.run reads project, agent. There is no kb or agent grant level. Those entries say what the action is about ; the levels you can actually grant at are the six in the table above, plus org and platform.
Reading this column as the set the engine evaluates is a known trap, and it is a different question from where a grant may be written.
Some actions list more than one real level, for example project, usecase. Those can be granted broadly or narrowly, and the narrow form is what lets you say "this one use case".
Remember that a wildcard target narrows what someone may do where they already are, while an explicit target establishes access to that one object. See wildcard and explicit targets .
Actions are fixed. You cannot create, rename or delete one. You bundle them into roles .
There are 128 actions across 26 modules.
Action What it allows Can be granted at account.manage.selfMy own account: profile, password, MFA, SSO link self app.openOpen Studio / Hub / Superadmin app org.enterOrg switcher / select-org org permission.view.selfMy own effective permissions self search.globalGlobal search box org
Action What it allows Can be granted at branding.manageBranding / whitelabel org invitation.view.selfMy pending invitations self member.inviteInvite / add member org member.removeRemove member org member.role.manageChange member role org member.viewMembers screen org mfa.policy.manageMFA policy org orgsettings.manageOrg settings org sso.manageSSO providers org sso.viewSee which SSO providers are configured org
Action What it allows Can be granted at project.createCreate project org project.deleteDelete project project project.editProject settings project project.listProjects list org project.members.manageMembers tab, add / change role project project.viewOpen a project project
Action What it allows Can be granted at magauth.mode.manageEnforcement mode toggle org magauth.pap.manageAccess-control grid, grant / revoke org, platform magauth.request.createRequest access to a surface self magauth.request.decideAccess requests approve / deny org
Action What it allows Can be granted at usecase.createCreate use case project usecase.deleteDelete use case project, usecase usecase.docs.viewDocumentation view / export project, usecase usecase.editCanvas open + save project, usecase usecase.exportExport workflow JSON (prompts included) project, usecase usecase.generateAutobuild / generate project usecase.header.previewCode-activity header preview self usecase.importImport workflow project usecase.listUse-cases list project usecase.publishPublish / version snapshot project, usecase usecase.runRun / Execute CTA project, usecase usecase.unpublishUnpublish / withdraw a published version project, usecase usecase.validateValidate workflow / input project, usecase usecase.viewOpen use-case detail project, usecase
Action What it allows Can be granted at execution.access.requestRequest access to a redacted run project execution.cancelCancel a run project, usecase execution.children.viewChild executions drill-down project, usecase execution.confidential.viewRun that touched a personal connector or doc org execution.debugActivity timeline / debug view project, usecase execution.exportExport executions to Excel project, usecase execution.listHistory list project, usecase execution.payload.readInputs / outputs / variables payload project, usecase execution.shareShare my run with a person or the project self execution.stats.viewStats tiles / counts project execution.view.anyOpen anyone else's run project execution.view.ownOpen a run I started project, usecase
Action What it allows Can be granted at agent.editCreate / edit agent persona + prompt project, agent agent.prompt.previewPreview / enhance prompt project, agent agent.runRun a single agent ad hoc project, agent agent.viewAgents list / detail project
Action What it allows Can be granted at kb.createCreate KB project kb.deleteDelete KB / document project, kb kb.listKB list project kb.scheduleSchedule recurring URL crawl project, kb kb.searchSearch inside KB project, kb kb.syncURL crawl / SharePoint resync project, kb kb.uploadUpload document project, kb kb.viewOpen KB, browse documents project, kb
Action What it allows Can be granted at credential.connect.selfConnect my personal account (Outlook, Teams) org credential.manage.orgProject / org connections org credential.manage.platformPlatform credentials platform credential.manage.projectProject connections create / edit / remove project credential.view.orgSee org connections (tool picker) org mcpserver.manageExternal MCP servers org tool.invokeTool invoked at runtime project, usecase, tool tool.viewTools catalog (project / org) project, org
Action What it allows Can be granted at llmaccess.managePer-project model access project llmconfig.manageCreate / edit LLM config (API keys) org llmconfig.viewLLM configs list org
Action What it allows Can be granted at chat.attachAttach file to a message project, usecase chat.listConversations list (Studio) project chat.manageRename / delete conversation project, usecase chat.model.selectModel picker project, usecase chat.sendSend message project, usecase chat.startStart a conversation project, usecase chat.view.anyRead anyone else's conversation project chat.view.ownRead my own conversation project, usecase
Action What it allows Can be granted at artifact.viewGenerated artifact download project file.deleteDelete file project file.download.anyDownload anyone's file project file.download.ownDownload a file I uploaded project file.uploadUpload file (START node / chat) project
Action What it allows Can be granted at humantask.respondRespond to a human task self humantask.view.anySee anyone's tasks project humantask.view.ownMy tasks inbox self
Action What it allows Can be granted at schedule.manageCreate / edit / pause / resume project, usecase schedule.triggerTrigger now project, usecase schedule.viewSchedules list project, usecase
Action What it allows Can be granted at inbound_webhook.manageInbound webhooks create / rotate / edit project, usecase inbound_webhook.viewInbound webhooks list + delivery log project, usecase webhook.manageWebhooks create / rotate / edit project, usecase webhook.viewWebhooks list + delivery log project, usecase
Action What it allows Can be granted at quota.manageToken quotas / limits org quota.request.approveApprove / reject limit request org quota.request.selfAsk for a higher token limit, and see my own requests self usage.org.viewOrg usage + cost breakdown org usage.self.viewMy usage self
Action What it allows Can be granted at analytics.org.viewOrg analytics + export org analytics.platform.viewPlatform-wide dashboard platform analytics.project.viewProject analytics project analytics.usecase.viewUse-case analytics project, usecase
Action What it allows Can be granted at secret.manage.orgOrg vault read / write org secret.manage.projectProject managed secrets project secret.manage.selfMy own vault entries self
Action What it allows Can be granted at apikey.manageCreate / revoke API key project
Action What it allows Can be granted at notification.viewNotifications self
Action What it allows Can be granted at store.browseBrowse template store: listings, categories, detail, snapshot platform store.installPreview / install a store template into a project project store.managePublish / edit / remove store listings, upload store assets platform
Action What it allows Can be granted at testcase.manageCreate / edit / delete test cases project, usecase testcase.runRun test cases project, usecase testcase.viewTest cases list / detail / report project, usecase
Action What it allows Can be granted at ai_task.viewPoll async AI helper job status (enhance / docs / test cases) project
Action What it allows Can be granted at feedback.submitRate, re-rate or un-rate a run project feedback.viewFeedback list project
Action What it allows Can be granted at support.self.manageSubmit and track your own support tickets self
Action What it allows Can be granted at audit.viewAudit log read platform marketplace.manageMarketplace plans / subscriptions platform org.manageOrgs CRUD platform orggroup.manageOrg groups platform platform.settings.managePlatform settings / prompts / email platform support.manageSupport queries platform user.manageUsers CRUD / bulk import platform
© 2026 Magure, Inc.