Admin permissions reference
Reference of all organization-level permissions available in Retool roles.
Organization roles grant access to organization-wide settings. Object roles grant access to apps, resources, workflows, and agents. Both are configured from Settings > Roles.
The Plan column shows the minimum plan required to use each permission. Business+ means the permission is available on Business and Enterprise plans. Enterprise means it requires an Enterprise plan.
Some permissions automatically include others. When you select a parent permission, all child permissions are included:
- Edit queries includes View queries.
- Manage billing includes Manage user seats.
The UI automatically handles these dependencies when you configure roles.
Organization permissions
Organization permission scopes control access to administrative settings pages.
User management
| Permission | Description | Plan |
|---|---|---|
| Manage single sign-on (SSO) | Configure single sign-on integrations. | Enterprise |
| Manage user attributes | Define and manage custom user attributes. | Enterprise |
| View account details | View and manage account details. | Business+ |
| View users page with emails | View the users page with user emails. | Business+ |
Example
Create an Identity Manager role for your IT team to manage SSO and user provisioning without full admin access.
Query library
| Permission | Description | Plan |
|---|---|---|
| Edit queries | Create, edit, and delete queries in the library. | Business+ |
| View queries | View and use queries from the library. | Business+ |
Example
Create a Query Developer role for database experts to manage shared query templates.
Organization configuration
| Permission | Description | Plan |
|---|---|---|
| Manage Spaces | Configure and manage Spaces. | Enterprise |
| Manage internationalization | Configure language and localization settings. | Enterprise |
| Manage Retool API | Manage API access tokens and settings. | Enterprise |
| Manage source control | Configure Git integrations. | Enterprise |
| Manage usage analytics | View and configure analytics. | Business+ |
| Manage billing | View and manage billing settings. | Enterprise |
| Manage user seats | Assign and modify user seat types (builder, internal, or external). | Enterprise |
| View audit logs | Access audit log data. | Business+ |
Example
Create a Finance Admin role that grants access to billing and usage analytics only, allowing your finance team to monitor costs without accessing other settings.
Customization
| Permission | Description | Plan |
|---|---|---|
| Manage branding | Configure organization branding and styling. | Enterprise |
| Manage themes | Create and edit custom themes. | Business+ |
| Manage Retool Events | Configure and manage Retool Events. | Enterprise |
| Manage Retool External | Configure external user access and APIs. | Enterprise |
| Manage custom components libraries | Manage custom component libraries. | Enterprise |
Example
Create a Design Manager role for your design team to manage branding and themes.
Configuration
| Permission | Description | Plan |
|---|---|---|
| Allow access to unpublished releases | Grant access to edge/unpublished releases. | Business+ |
| Manage environments | Configure resource environments. | Enterprise |
| Manage configuration variables | Manage config variables. | Enterprise |
| Manage Retool AI | Configure AI features and settings. | Enterprise |
| Manage IAM credentials | Manage secrets and IAM integrations. | Enterprise |
| Manage observability | Configure monitoring and observability. | Enterprise |
Example
Create a DevOps Manager role that grants access to environments, config variables, and IAM credentials for your operations team.
Additional settings
| Permission | Description | Plan |
|---|---|---|
| Manage advanced settings | Access advanced organization settings. | Enterprise |
| Manage mobile settings | Configure mobile app settings. | Enterprise |
| Manage beta settings | Access and configure beta features. | Enterprise |
| Manage draft apps | Control draft app access and settings. | Business+ |
Object permissions
The object permissions feature is not yet available on self-hosted instances.
Object permission scopes let you use roles to grant access to Retool objects (apps, resources, workflows, and agents) rather than just organization settings. These scopes appear as a Universal object permissions category in the role editor and are available on the Enterprise plan.
Universal object permissions grant access to all objects of a given type across the organization.
Apps
| Permission | Description | Plan |
|---|---|---|
| View all apps | Grant Use access to all apps. | Enterprise |
| Edit all apps | Grant Edit access to all apps. | Enterprise |
| Own all apps | Grant Own access to all apps. | Enterprise |
Resources
| Permission | Description | Plan |
|---|---|---|
| View all resources | Grant Use access to all resources. | Enterprise |
| Edit all resources | Grant Edit access to all resources. | Enterprise |
| Own all resources | Grant Own access to all resources. | Enterprise |
Workflows
| Permission | Description | Plan |
|---|---|---|
| View all workflows | Grant Use access to all workflows. | Enterprise |
| Edit all workflows | Grant Edit access to all workflows. | Enterprise |
| Own all workflows | Grant Own access to all workflows. | Enterprise |
Agents
| Permission | Description | Plan |
|---|---|---|
| View all agents | Grant Use access to all agents. | Enterprise |
| Edit all agents | Grant Edit access to all agents. | Enterprise |
| Own all agents | Grant Own access to all agents. | Enterprise |
Example
Create a Resource Administrator role with Own all resources to allow a platform team to manage all data connections without granting full admin access.
Updated app builder
| Permission name | Description | Business | Enterprise |
|---|---|---|---|
| Build apps in the AI-powered app builder | Control access to the updated app builder. |
Example
Create a New App Builder role to allow specific teams to access the AI-powered app builder.