Skip to main content
Apragya AI
Docs · Getting Started

Invite your team and assign roles

Bring your team into the tenant with the right access. Covers built-in roles, custom roles, and per-app permissions via RBAC v3.

Apragya AI ships with five built-in role tiers - SaaS Admin, Platform Developer, Org Admin, Member, and Client. Most teams only ever touch the last three. Custom roles let you carve out tighter access (e.g., "Finance Manager who can approve invoices but not edit the CRM").

Send an invite

  • Admin Settings > Users > Invite.
  • Provide email + initial role. The recipient gets an email with a one-click acceptance link valid for 7 days.
  • Bulk invite: paste up to 50 emails at once, choose the role applied to all.
  • Pre-assign the apps the new user should land in - a Sales user might land in CRM + Sales & POS, a Finance user in Finance + Invoice & AP.

Built-in roles

  • SaaS Admin: full platform access, manages tenants and platform-level settings.
  • Platform Developer: builds platform features. Can read most things, write to platform config.
  • Org Admin: full control inside your tenant - users, apps, agents, billing, RBAC.
  • Member: day-to-day app users. Permissions further refined via RBAC v3 per-app matrices.
  • Client: external portal access for customer-facing flows (read-only ticket views, contract signing).

Per-app permissions with RBAC v3

Roles alone aren't fine-grained enough for real enterprise teams. RBAC v3 layers per-app permission matrices on top: for each (role, app), pick exactly which actions (view, create, edit, delete, approve) are allowed. Org Admin > RBAC opens the matrix editor.

Plan-feature gates run BEFORE RBAC. A role's permission can still be denied if the underlying capability isn't included in your plan - the sidebar hides modules off-plan and mutating routes return 403. Upgrade the plan first, then the RBAC permission applies.

Custom roles

Need finer control than the five built-ins? Org Admin > RBAC > Create Role lets you clone any built-in and tweak the permission matrix. Custom roles are tenant-scoped - they don't leak across tenants.

SSO for enterprise tenants

If your team uses Okta, Azure AD, Google Workspace, or any SAML 2.0 / OIDC IdP, wire SSO before bulk-inviting. JIT provisioning auto-creates the user on first login with the role mapped from your IdP groups. See the SAML SSO setup guide for the full flow.

Need help building this? Talk to a real engineer

← All docs
Ask Vippy anything