For the complete documentation index, see llms.txt. This page is also available as Markdown.

Roles and Permissions

Cakewalk Agent Access has two roles: Admin and Member. This page defines what each can do.

Cakewalk Agent Access uses two roles: Admin and Member. Every User has exactly one.


πŸ“– Key Concepts

  • Admin: Configures and operates Cakewalk Agent Access. Manages every Agent, Connection, User and Policy across the organization.

  • Member: The day-to-day role for everyone who isn't an Admin. Employees with this role connect to third-party apps, set up Agents and respond to approval prompts.

πŸ’‘ Why this matters: Your role determines what you see when you log in and what actions you can take. Admins configure governance for the organization; Members manage their own Connections, Agents and approval prompts.


πŸ›  Admin Capabilities

An Admin can:

  • View the org-wide Dashboard and Agent Activity

  • Manage Connections (add to catalog, suspend, remove from governance)

  • Manage Agents (pre-register, suspend, restrict, restore, unrestrict)

  • Manage Users (invite, edit attributes, end sessions, revoke connections, remove)

  • Author and activate Policies

  • Inspect the Audit Log for any session in the organization

User attribute edits are available only when HRIS sync is not configured. When HRIS sync is active, User attributes flow from your company's HRIS or IdP and are read-only across the product.

Admins are typically the CISO, the security team or the IT lead who owns AI agent governance.


πŸ›  Member Capabilities

A Member can:

  • Connect to third-party apps (Connections) the Admin has added to the catalog

  • Set up Agents through the MCP Gateway

  • Receive and respond to MCP elicitation prompts when an action requires approval

  • See their own Connections and Agents and the status of each

  • See and edit their Profile Settings (HRIS-synced fields are read-only)

Members do not see other Members' Connections, Agents or sessions. They cannot create Policies. They cannot pre-register, suspend or restrict Agents: those are Admin-driven lifecycle states.


Last updated

Was this helpful?