AI Studio permission matrix

This page summarizes the AI Studio permission matrix for quick reference during design, configuration, and troubleshooting.

Reference table

Domain

Typical read actions

Typical write actions

Users and roles

View members, roles, and role assignments

Create, change status, assign roles, and delete

Connectors and tasks

View connections and execution status

Create, edit, run, pause, and delete

Catalog and knowledge bases

Browse assets, sources, and bindings

Create, update semantics, bind, and delete

Workflows

View DSL, versions, and executions

Create, edit, run, pause, and publish

Agents

View configurations, versions, and sessions

Bind capabilities, create versions, publish, and automate

Monitoring

View jobs, SQL history, and logs

Export records or manage alert rules (if enabled)

How to use this reference

  1. Confirm the product version, workspace, and feature flags in your environment.

  2. Use the table to identify the relevant capability or troubleshooting approach, then follow the corresponding guide to complete the configuration.

  3. Run a minimal test of compatibility, permissions, or limits; do not rely solely on whether an item appears in the interface.

  4. Save the error message, request ID, and time of occurrence to support cross-service troubleshooting.

Product entry and core objects

Item

Current implementation

Page entry

Reference pages do not map to a single runtime entry.

Service contract

Enumerations come from the current frontend registration, Core IAM actions, backend routes, and MatrixOne SQL capabilities; the deployment contract takes precedence over the documentation snapshot.

Core objects

Enum, Feature flag, Permission action, HTTP status, Connector type, Operator

Authorization and limitations

Note

Reference information does not replace the change history. Before you upgrade, also check the release notes and compatibility guidance.