Skip to main content

Configuring platform permissions

The permissions system gives admin users control over which users and agents can access specific parts of the platform. To start, this covers two things: which agents and workflows each user can see, and which student data fields each team has access to.

If you don't configure anything, your platform works exactly as it does today.

Key concepts

Teams

A team is a group of users and agents. Teams are the building block of the permissions system.

  • Users can belong to multiple teams.

  • Each agent belongs to exactly one team.

  • Users only see agents that are on the same teams they're on.

  • Admin users can see all agents on the platform regardless of team assignments.

  • Every school starts with one school-wide team (named after your institution) that includes all existing users and agents.

Property groups

A property group is a collection of student data fields (constituent properties). Assigning a property group to a team controls which fields that team can view on student records.

  • Fields can belong to more than one property group.

  • Any field not assigned to a specific group is "ungrouped."

  • All teams can see ungrouped fields by default. Admins can change this if needed.

  • Users on multiple teams see the combined set of fields across all their teams.

What users will see

Once permissions are configured at your institution, each user will see:

  • Only the agents and workflows on their teams

  • Only the student data fields their team has been given access to on constituent records

Admin users have access to everything on the platform by default.

For regular users, the default is also unchanged: all users are automatically added to the school-wide team, which starts with access to all ungrouped fields. Since all properties begin as ungrouped, regular users see all agents and constituent data as they do today, until an admin actively configures teams and property groups.

Agents and property access: The property restrictions on a team also apply to agents on that team. An agent can only draw on the property data available to its team when composing a response. This doesn't filter the agent's output directly, but it limits what information the agent has access to.

A note on related settings: if you've previously configured the Allowed properties setting on a constituent knowledge tool, property groups supersede that setting — both can be active at the same time without issue. Property permission types (read, modify, etc.) are a separate concept: they define what agents can do with data, not which properties they can see, and are currently the same across all agents.


For admins: Setting up permissions

The permissions dashboard is available to admin users only. Go to Permissions in the left sidebar to get started.

Step 1: Create a team

  1. On the permissions dashboard, click the button to create a new team.

  2. Give it a name (for example, the name of a department or function at your institution).

  3. Add users.

  4. Save.

Step 2: Add agents or workflows to a team

You can do this in two ways:

  • From the team's detail page, go to the agents/workflows tab and add from there.

  • From an individual agent's page, click Agent permissions at the top.

When creating a new agent, you'll be prompted to assign it to a team during setup. Every agent must belong to a team.

Step 3: Create a property group (optional)

If you want to limit which student data fields certain teams can see:

  1. Go to the constituent properties page. All users can view this page; only admins can create or modify property groups.

  2. Select the fields you want to group. You can select in bulk or field by field.

  3. Add them to a new or existing property group. When creating a new group, you can also assign it to teams in the same step.

Step 4: Assign a property group to a team

  1. From the permissions dashboard, click on the team.

  2. Go to the Data access tab.

  3. Click edit data access, and assign the property group(s) for that team. Make sure to click Save.

Default behavior

Out of the box, all student data fields are ungrouped, and all teams have access to ungrouped fields. Your existing setup keeps working without any action required.

When you're ready to restrict access, a good starting point is to create teams for departments or functions that need different data access, then build property groups around what each team should see. Your school-wide team will continue to include all users and agents until you reorganize.

💡 Questions about how to structure permissions for your institution? Reach out to your CollegeVine success manager.

Did this answer your question?