Skip to main content
Access in a GC AI organization depends on four controls:
  1. Organization role determines who can manage the organization.
  2. Access tier determines which product permissions a member is eligible to use.
  3. Product roles grant specific permissions.
  4. Resource sharing determines which private content the member can open.
All four controls apply. A role cannot grant a permission that the member’s access tier does not support, and a product permission does not reveal private content that has not been shared with the member.

Organization roles

Every organization member is either an Admin or Member.

Admin

Admins can:
  • Invite new members to the organization
  • Remove members from the organization
  • Manage access tiers and product roles
  • Update organization details
  • Enable or disable public chat sharing for the organization (when disabled, users see a notice and sharing actions are blocked)
  • Enable or disable Google Drive import for all members
  • Manage Agent Connector policies for the organization
  • Opt in to Claude Fable 5 and opt out of AI model providers
  • Manage web search approval settings
  • Manage billing and seat settings
Admin grants organization management access. It does not grant product permissions by itself.

Member

Members cannot administer the organization or manage organization membership. Their product access comes from their access tier, assigned roles, and shared resources. Both Admins and Members can connect their own accounts under Agent Connectors, subject to the organization’s connector policy.

Product roles

Product roles collect permissions that you can assign to members. Open Settings → Roles to review or create them.

Built-in roles

  • Standard access grants GC AI’s standard product permissions to members with a Legal seat or active trial.
  • Admin grants organization management access and no product permissions.
GC AI manages built-in roles, so you can review but not edit them.

Custom roles

Organization admins can create custom roles with the exact product permissions a team needs. You can assign a role directly to a member or to a user group. A member receives the combined permissions from every direct and group role. Each permission shows which access tiers can use it. Assigning a broader role does not expand the member’s access tier. For example, a Stakeholder seat cannot use Main Chat or project permissions even if an assigned role contains them. Deleting a custom role removes its assignments. It does not delete members, groups, or content.
Your organization may need access to custom roles and Stakeholder seats. Contact your account team if Settings → Roles does not appear.

Access tiers

Access tiers set the maximum permissions a role can activate: See Stakeholder seats for the current permission list and organization-scoped behavior.

How access combines

When a member opens a resource, GC AI checks:
  1. Do the member’s roles or View grants provide the required permission?
  2. Does the member’s access tier support that permission?
  3. Can the member access this resource through a direct share, group share, or organization-wide setting?
The member gets access only when each required check passes. A direct or group View grant provides the Access shared Views permission for that content. The member does not need a separate product role for the shared View.

Agent Connector access

A connector has three layers:
  1. Enabled by the organization
  2. Connected by the member
  3. Tool permissions allowed by the member
The three layers determine whether GC AI can use a connector tool. It must be enabled by the organization, connected by an organization member, and allowed by that member’s tool permissions. For most connectors, organization admins control whether access is Disabled, Read-only, or Full access for all members or specific members in Settings → Policies → Connector policies. Only an organization admin can set a per-member exception.
Agent Connectors and Document Storage use separate access controls, although they may share the same member account connection.
See Agent Connectors for setup steps, default behavior, and policy details.

Content privacy

By default, new content in GC AI is private:
  • Individual chats are only visible to their creator, unless you share them or add them to a shared project
  • Skills are private unless shared
  • Company Profiles can be managed privately
  • Content sharing requires an explicit action, including setting a project to Organization visibility

Sharing controls

Users can control sharing through:
  • Individual sharing with specific members
  • Sharing with user groups
  • Organization-wide sharing options
  • Granular permission settings
  • Revocable access controls
Access granted directly and through user groups is combined. When several grants apply, GC AI uses the highest access level. Group roles control group management and do not change access to shared resources.
Last modified on September 17, 2026