Roles
Your workspace has two built-in roles:Custom roles
When view-only is too little and admin is too much, create a custom role. On the Roles tab, admins can name a role, tick exactly the permissions it grants, and assign members to it:- Edit mappings — approve, reject, remap, create canonical entities, bulk-approve, and edit the concept registry.
- Edit context — create, edit, and permanently delete the terms and variables your AI reads.
- Run backfills — trigger historical data backfills for connected sources.
Roles govern what someone can change in the context layer — the shape of the
governed data your AI tools read. They don’t change what data your connected tools can
query over MCP; that’s gated by your integrations.
Activity
The Activity tab is an admin-only feed of every query your AI tools have run against your context layer, newest first. Each entry shows who ran it, the source and tool it used, and whether it succeeded, and you can expand one to see the query itself or filter the feed to narrow in. It’s how you audit what your connected tools have actually been asking for.Manage members
Open Governance in the sidebar. The Members tab lists your members, their email, and their role; the Roles tab is where admins create and edit custom roles; and the Activity tab (admins only) shows the query feed above.1
Find the member
Each row shows a person’s name, email, and current role. Your own row is marked
You.
2
Change their role
If you’re an admin, use the role control on a member’s row to pick Admin,
Member, or one of your custom roles. Members see View only here instead.
A workspace always needs at least one admin. If you’re the only admin, make someone
else an admin before stepping down from the role.