Skip to main content
Version: Next

User Roles

Obot uses role-based access control to manage what users can do in the MCP Platform. Each role has different permissions and sees different parts of the interface.

Available Roles

Owner

Full platform management plus the ability to assign the Owner and Auditor roles to users.

Admin

Full platform management: MCP Management, Chat Management, User Management, and App Preferences. Cannot assign the Owner or Auditor roles.

Power User+

All Power User permissions plus the ability to create MCP Registries and share MCP servers with other users.

Power User

All Basic User permissions plus publishing custom MCP servers (personal use only) and viewing Audit Logs and Usage statistics for their activity.

Basic User

Connect to MCP servers, use Obot Chat, and create projects and threads.

Auditor

Add-on permission that grants read-only access to sensitive data across the platform. Sensitive data (MCP request/response bodies, chat threads, and task runs) can only be viewed by users with this role. All other roles, including Owner, see only metadata for these resources. Can be combined with any other role.

Role Comparison

CapabilityBasicPowerPower+AdminOwner
Connect to MCP serversYesYesYesYesYes
Use Obot ChatYesYesYesYesYes
View Audit LogsYes*Yes*Yes**Yes**
View UsageYes*Yes*YesYes
Publish personal MCP serversYesYesYesYes
Share MCP servers through registriesYesYesYes
Manage FiltersYesYes
Server SchedulingYesYes
Chat ManagementYesYes
User ManagementYesYes
App PreferencesYesYes
Assign Owner/Auditor rolesYes

* Only for servers they deployed

** Metadata only. Full request/response bodies require the Auditor role. Owners can assign Auditor to themselves, but this is an explicit action to prevent accidental exposure to sensitive data.

Managing User Roles

Updating a User's Role

  1. Navigate to User Management > Users
  2. Click the three vertical dots on the user's current role
  3. Click Update Role
  4. Select the new role

Default Role for New Users

Configure the default role for new users on the User Management > User Roles page.

Pre-Assigning Roles

To grant admin or owner access to users before they log in, set these environment variables during deployment. See Enabling Authentication for details.

OBOT_SERVER_AUTH_ADMIN_EMAILS=admin@example.com,admin2@example.com
OBOT_SERVER_AUTH_OWNER_EMAILS=owner@example.com