Permissions and sharing

Who can do what, how much of it, and what they can see of each other’s work.

Groups grant; they never deny

Permissions are named switches. Everyone starts from a baseline, and each group a person belongs to can only add to it. That keeps the question “why can this person not do X?” answerable: nothing they are in took it away.

An administrator’s view of a user lists every permission with where it came from — administrator, baseline, or the groups that granted it. Everyone can see their own under Settings → Account → What you can do, in plain words.

Administrators hold every permission. A few worth knowing, all off by default:

PermissionAllows
Use the APIMaking API tokens and signing in devices such as the LLeMbas CLI.
Run commandsAgent chats on linked devices.
Open a terminalThe terminal panel in an agent chat.
Read the audit logThe audit log, in the interface and over the API.
Grant creditsTopping up and adjusting other people’s credits and choosing their plans.
Manage data groupsPersonal data groups and moving one’s own records between them.

Models can also be limited to chosen groups.

Quotas

Groups can set limits on five things:

LimitChecked
Tokens a monthbefore a reply starts
Replies at oncewhen you send
Agent timewhile an agent works
Images a daybefore a picture is drawn
Helpers a replywhen a reply sends helpers
  • Across several groups, the highest limit wins — a second group can only give more.
  • A group that does not set a limit contributes nothing.
  • Zero means no limit, and wins outright.
  • Administrators are unlimited.
  • Usage is counted even when a reply was stopped or failed — the endpoint charged for those tokens too.

For money-like limits, see Credits.

Sharing

You can share a knowledge base, a note, a skill or a report with a person or a group. Sharing is read-only: the owner alone edits and deletes. Every listing has a Shared with me filter.

  • The share panel on each item adds or removes one grant at a time, and what you see there is what is stored.
  • Memories are never shared — they are records about a person.
  • Reading somebody’s shared report does not mark it read for them.

Data groups

A data group keeps one provider’s models away from the data another provider’s models have been given. Every connection is in one group, and its models read only that group’s memories, notes, skills, knowledge and reports. A chat stays in the group it started in.

  • Data belongs to a group, not to a connection. Moving a connection to another group moves no data: from then on, that provider reads the other group.
  • A provider moved out of a group keeps whatever it was already sent; one moved in can read everything the group holds. The screens that move a connection say so.
  • Your own view of your library always shows every group — the separation is between providers, not between you and your records.
  • With Manage data groups, a person can map connections to groups for themselves and move their own records.

Administrators set up groups under Admin → Data groups.