- Organization role determines who can manage the organization.
- Access tier determines which product permissions a member is eligible to use.
- Product roles grant specific permissions.
- Resource sharing determines which private content the member can open.
Organization roles
Every organization member is either an Admin or Member.Admin
Admins can:- Invite new members to the organization
- Remove members from the organization
- Manage access tiers and product roles
- Update organization details
- Enable or disable public chat sharing for the organization (when disabled, users see a notice and sharing actions are blocked)
- Enable or disable Google Drive import for all members
- Manage Agent Connector policies for the organization
- Opt in to Claude Fable 5 and opt out of AI model providers
- Manage web search approval settings
- Manage billing and seat settings
Member
Members cannot administer the organization or manage organization membership. Their product access comes from their access tier, assigned roles, and shared resources. Both Admins and Members can connect their own accounts under Agent Connectors, subject to the organization’s connector policy.Product roles
Product roles collect permissions that you can assign to members. Open Settings → Roles to review or create them.Built-in roles
- Standard access grants GC AI’s standard product permissions to members with a Legal seat or active trial.
- Admin grants organization management access and no product permissions.
Custom roles
Organization admins can create custom roles with the exact product permissions a team needs. You can assign a role directly to a member or to a user group. A member receives the combined permissions from every direct and group role. Each permission shows which access tiers can use it. Assigning a broader role does not expand the member’s access tier. For example, a Stakeholder seat cannot use Main Chat or project permissions even if an assigned role contains them. Deleting a custom role removes its assignments. It does not delete members, groups, or content.Your organization may need access to custom roles and Stakeholder seats. Contact your account team if Settings → Roles does not appear.
Access tiers
Access tiers set the maximum permissions a role can activate:
See Stakeholder seats for the current permission list and organization-scoped behavior.
How access combines
When a member opens a resource, GC AI checks:- Do the member’s roles or View grants provide the required permission?
- Does the member’s access tier support that permission?
- Can the member access this resource through a direct share, group share, or organization-wide setting?
Agent Connector access
A connector has three layers:- Enabled by the organization
- Connected by the member
- Tool permissions allowed by the member
Agent Connectors and Document Storage use separate access controls, although they may share the same member account connection.
Content privacy
By default, new content in GC AI is private:- Individual chats are only visible to their creator, unless you share them or add them to a shared project
- Skills are private unless shared
- Company Profiles can be managed privately
- Content sharing requires an explicit action, including setting a project to Organization visibility
Sharing controls
Users can control sharing through:- Individual sharing with specific members
- Sharing with user groups
- Organization-wide sharing options
- Granular permission settings
- Revocable access controls