> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Role-Based Access Control (RBAC)

> Comprehensive user management and permission controls for your organization

Neo Agent's Role-Based Access Control (RBAC) system provides comprehensive user management and permission controls for your organization. This feature allows administrators to control who has access to different parts of the Neo Agent platform, manage user roles, share specific workflows, and track all user activity through detailed audit logs.

RBAC ensures that team members have appropriate access levels based on their responsibilities while maintaining security and operational oversight across your MSP organization.

## User Management

### Dashboard Overview

The RBAC feature can be found under the **Roles & Access** section and provides a centralized view of all users in your organization, showing their roles, status, and recent activity. You can quickly see who has access to what and make adjustments as needed. Only users with **ADMIN** role can view/manage other users.

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/rbac-screen.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=41467dadaba81343c80235cd8dd9a159" alt="RBAC Dashboard showing all users in organization with roles and status" width="2854" height="1354" data-path="images/rbac/rbac-screen.png" />
</Frame>

### User Roles and Permissions

Neo Agent supports different user roles with varying levels of access:

* **Admin:** Full access to all features and user management capabilities
* **User:** Regular Users can create any workflow as well as can edit any workflow shared with them
* **Viewer:** Read-only access, can view execution history of any workflow shared with them, but cannot create or edit any workflow

<Info>
  Users with ADMIN role have access to all dashboard sections. Users with USER/VIEWER role need to be granted access to restricted dashboard sections.
</Info>

### Workflow access applies everywhere — including Neo Support

A user's workflow access (their role, the workflows they created, and the workflows shared with them) is enforced consistently across every surface:

* **Dashboard:** the workflow list, editor, run-now, version history, and stats only cover workflows the user can access.
* **Neo Support chat:** when a user asks the Neo Support Agent to list, inspect, edit, or train workflows, the agent operates under **that user's** permissions. It only sees the workflows they can see, and edits (including training suggestions) require edit access — a Viewer, or a User the workflow isn't shared with, will be told to ask an administrator instead.
* **Training suggestions:** reviewing or applying a suggested change to a workflow requires access to that workflow.

There is no way to use the Neo Support Agent to reach a workflow the user couldn't reach on the dashboard.

### Access Denied Scenarios

When users don't have the necessary permissions to access the dashboard, they'll encounter an access denied screen that clearly explains the restriction and provides contact information for administrators:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/dashboard-access-denied.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=febcd928bfb9f295e11b523935c82cd0" alt="Dashboard Access Denied screen with explanation and administrator contact information" width="2832" height="1392" data-path="images/rbac/dashboard-access-denied.png" />
</Frame>

This screen ensures users understand why access is restricted and provides a clear path to request access through the listed administrators.

### Inviting New Users

To add new team members to your Neo Agent organization:

1. **Access User Management:** Navigate to the Roles & Access section
2. **Click Invite User:** Select "Invite New User" to open the invitation form
3. **Enter User Details:** Provide the user's name, email address, and assign their role
4. **Send Invitation:** The system automatically sends an email invitation to the new user

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/invite-new-user.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=18ad0bc4ba1abb5288fb2be8d9665c75" alt="Invite New User form with name, email, and role selection" width="1182" height="864" data-path="images/rbac/invite-new-user.png" />
</Frame>

#### Example of Email:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/invitation-email.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=d8db8a15303b9c6ed91f412cad097a9c" alt="Sample invitation email sent to new users" width="662" height="659" data-path="images/rbac/invitation-email.png" />
</Frame>

New users receive an email invitation with instructions to access the Neo Agent dashboard and will appear as "Pending" until they complete the activation process.

## Permission Management

### Dashboard Tab Access

Control which dashboard sections users can access through granular permission settings:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/update-permissions.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=ba9e062412b7a0e80d87f7039c84d525" alt="Update permissions interface showing granular dashboard tab access controls" width="1780" height="1260" data-path="images/rbac/update-permissions.png" />
</Frame>

Available restricted access tabs include:

* **Integrations:** Configure PSA, RMM, and other system integrations
* **Analytics:** View workflow performance and system analytics
* **Phone Agent:** Manage AI Phone Agents settings and call history
* **Companies:** Manage client companies and organizations
* **Profile:** View and edit user profile information
* **Billing:** Manage billing and subscription information
* **Settings:** Configure system settings and preferences
* **Feedback:** Provide feedback about workflows

#### Restricted Access Experience

When users attempt to access a dashboard section they don't have permission for, they'll see a clear access restriction message:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/tab-restricted-access.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=44cbf8b3b4186f06d49d1b0b211d9d4f" alt="Tab restricted access screen with explanation and guidance" width="2860" height="1392" data-path="images/rbac/tab-restricted-access.png" />
</Frame>

This screen provides users with information about the restriction and guidance on how to request access from their administrator.

### Workflow Sharing

Share specific workflows with individual users while maintaining control over access:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/share-workflows.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=1b69f7d515a854c5064e779df573d508" alt="Workflow sharing interface for selecting users and workflows" width="1792" height="1262" data-path="images/rbac/share-workflows.png" />
</Frame>

#### Sharing Workflows

1. **Select User:** Choose the team member who needs access
2. **Choose Workflows:** Select specific workflows to share from your available list
3. **Grant Access:** Confirm the sharing permissions

Shared workflows appear in the user's dashboard alongside any workflows they've created themselves.

### Chat Agent Access

The **Chat Agent Access** tab controls who on your team may *message* each internal chat agent. This is separate from workflow sharing and from dashboard tab access: it governs messaging only — not who can see or edit the agent's configuration.

<Frame>
  <img src="https://mintcdn.com/neoagent/tYjYEqj4jjh2HqWR/images/rbac/chat-agent-access.png?fit=max&auto=format&n=tYjYEqj4jjh2HqWR&q=85&s=93aae4d42909446567b4b36928e7cab5" alt="Chat Agent Access tab listing each chat agent in a table with a 'Who can message it' dropdown and a People column" width="1570" height="840" data-path="images/rbac/chat-agent-access.png" />
</Frame>

For each chat agent, an admin can choose one of three modes:

| Option                    | Who can message the agent                                                                     |
| ------------------------- | --------------------------------------------------------------------------------------------- |
| **Everyone on your team** | Anyone on your team — the default                                                             |
| **Admins only**           | Your admins only                                                                              |
| **Specific people**       | Admins, plus the individual people you choose (uses the same user picker as workflow sharing) |

Only admins can change these settings. The mode applies to every internal chat agent, including the **Neo Support Agent** — because that agent can act on your Neo setup, many teams set it to **Admins only** while leaving everyday helpers open to the whole team. Agents that serve end users through a [channel](/chat-agents/channels) are governed by that channel instead, not by this tab.

See [Who can chat with the agent](/chat-agents/building-a-chat-agent#who-can-chat-with-the-agent) for how this appears when building an agent.

### API Keys

The **API Keys** tab is where admins create and manage keys for the [Neo public API](/developers/introduction) — the credentials your own scripts and integrations use to call Neo programmatically.

From [**Roles & Access** → **API Keys**](https://dashboard.neoagent.io/rbac?tab=api-keys) an admin can:

* **Create** a key, with an optional expiry. The full key is shown **once**, right after creation — copy it then, as it can't be retrieved later.
* **Rotate** a key — issues a replacement immediately while the old key keeps working for 24 hours, so you can roll it over without downtime.
* **Revoke** a key — disables it immediately and permanently.

Only admins can manage API keys. See [Authentication](/developers/authentication) for how to use a key once you've created one.

## Activity Tracking

### Comprehensive Audit Trail

Neo Agent maintains detailed activity logs for all user actions and administrative changes:

<Frame>
  <img src="https://mintcdn.com/neoagent/67c8YiVlnWW7Df07/images/rbac/activity-history.png?fit=max&auto=format&n=67c8YiVlnWW7Df07&q=85&s=7e2667627d7944189789380c4fd3981e" alt="Activity History showing comprehensive audit trail of user actions" width="1780" height="1092" data-path="images/rbac/activity-history.png" />
</Frame>

### Tracked Activities

The system automatically logs:

* **Workflow Sharing:** When workflows are shared or access is revoked
* **Role Changes:** Updates to user roles and permissions
* **User Management:** User creation, activation, enabling, and disabling
* **Permission Updates:** Changes to dashboard tab access
* **Announcement Subscriptions:** Email notification preferences

### Activity Details

Each audit entry includes:

* **Timestamp:** When the activity occurred
* **User:** Who performed the action
* **Activity Type:** What type of change was made
* **Details:** Specific information about the change

## Managing User Status

### User Status Types

Users can have different statuses within your organization:

* **Active:** Full access according to their role and permissions
* **Inactive:** Temporarily disabled access while preserving user data
* **Pending:** Invited but not yet activated their account

## Announcement Notifications

### Email Subscription Management

Control who receives Neo Agent announcement emails through the RBAC system:

Users can be subscribed or unsubscribed from announcement emails while maintaining their access to dashboard notifications.

## Best Practices

<Tip>
  Start with minimal permissions and gradually expand access as users become familiar with the platform. This approach maintains security while ensuring smooth onboarding.
</Tip>

### Access Patterns

* **Principle of least privilege** for production changes
* **Separate roles** for workflow authors vs operators
* **Read-only access** for auditors
* Use group-based permissions for larger teams to simplify onboarding

### Common Pitfalls

<Warning>
  Missing permissions cause workflows to fail silently; review Event History and role scopes. Overlapping roles can create confusion; standardize a role catalog.
</Warning>

<Info>
  RBAC features require administrative privileges. Contact your system administrator if you need to modify user permissions or roles.
</Info>

The RBAC system provides the foundation for secure, organized access management across your Neo Agent deployment, ensuring each team member has the right tools while maintaining operational security and oversight.
