Skip to content
ChangelogBook a demoSign up

AI Decisioning permissions

AudienceWorkspace admins and team leads who manage access to AI Decisioning.

AI Decisioning permissions are managed through roles, the same system that controls access to sources, destinations, and other Hightouch products. A role determines what each team member can modify in AI Decisioning, and which agents they can work with.


Overview

Every workspace member can view AI Decisioning resources—agents, messages, goals, collections, and configuration. Editing requires one of two capabilities, granted per role on the AI Decisioning tab of the role editor:

CapabilityWhat it allowsBest for
Edit contentCreate and edit messages, variables and variants, tags, collections, and content suggestions, and send preview messages.Marketing and content teams managing message copy, variants, and collections.
Manage agentsEverything in Edit content, plus agent creation and lifecycle, goals, feature matrices, channels, and configuration.Team leads responsible for agent setup, goals, channels, and configuration.

In addition to these capabilities, a role controls which agents the group can work with, based on the parent model each agent targets. See Agent access by parent model.

A few rules apply regardless of role configuration:

  • Workspace admins always have full AI Decisioning access, on all parent models.
  • The other pre-built roles (Editor, Draft Editor, Viewer) don't include AI Decisioning editing. To give a non-admin group edit access, use a custom role.
  • Every workspace member can see all AI Decisioning resources.

Managing access

  1. Go to Settings > Groups.
  2. Edit custom role.
  3. Open the AI Decisioning tab.
  4. Under Users can, select Edit content, Manage agents, or both. Manage agents includes everything Edit content allows.
  5. Under Agent access by parent model, choose whether the role applies to all parent models or only specific parent models.

The AI Decisioning tab of the role editor, showing the Edit content and Manage agents capabilities and agent access by parent model


Agent access by parent model

Every agent targets a parent model—the population of users it makes decisions for. Roles can limit which parent models a group works with:

  • All parent models — The role's capabilities apply to every agent in the workspace, including agents created later on new parent models.
  • Specific parent models — The role's capabilities apply only to agents targeting the selected parent models. Agents on other parent models remain visible but read-only.

Agent access by parent model with specific parent models selected

Parent model access scopes everything tied to an agent: creating agents on that parent model, starting and pausing them, and editing their messages, goals, splits, and experiments. Feature matrices are also scoped to the parent model they're built on.

Workspace-level resources—channels, send events, and collections—aren't tied to a parent model, so they only require the corresponding capability.

For example, an "Email content team" role with Edit content and access to the Customers parent model can edit message copy and variants on agents targeting Customers, but can't start or pause those agents, and can't edit messages on agents targeting other parent models.


Permission details

The tables below show what each action requires. Actions on agents and their resources also require access to the agent's parent model.

Agents

ActionRequires
View agentsAny workspace member
Create agentManage agents
Edit agent nameManage agents
Run agent or run all agentsManage agents
Start, pause, or initialize agentManage agents
Edit agent configurationManage agents
Delete agentManage agents

Messages

ActionRequires
View messagesAny workspace member
Add messages (individual or CSV upload)Edit content
Edit message content (variables, variants)Edit content
Edit message name and configurationEdit content
Apply content suggestionsEdit content
Send a preview or test messageEdit content
Bulk edit message contentEdit content
Delete or restore messagesEdit content
Enable or disable messages (individual or bulk)Manage agents

Tags

ActionRequires
View tagsAny workspace member
Edit message and variant tagsEdit content
Generate tagsEdit content

Collections

ActionRequires
View collectionsAny workspace member
Create, edit, or delete collectionsEdit content

Goals

ActionRequires
View goalsAny workspace member
Add, edit, or delete goalsManage agents

Feature matrices

ActionRequires
View feature matricesAny workspace member
Create, edit, duplicate, or delete feature matricesManage agents

Configuration

ActionRequires
View configurationAny workspace member
Edit general, scheduling, and localization configurationManage agents
Edit user features configurationManage agents
Create, edit, or delete channelsManage agents
Toggle channel enabled or disabledManage agents
Edit send event configurationManage agents

The AI Decisioning REST API currently requires the workspace admin role for write operations.

Ready to get started?

Jump right in or a book a demo. Your first destination is always free.

Book a demoSign upBook a demo

Need help?

Our team is relentlessly focused on your success. Don't hesitate to reach out!

Feature requests?

We'd love to hear your suggestions for integrations and other features.

Privacy PolicyTerms of Service