Skip to main content

Admin permissions reference

Organization roles grant access to organization-wide settings. Object roles grant access to apps, resources, workflows, and agents. Both are configured from Settings > Roles & Permissions.

The Plan column shows the minimum plan required to use each permission. Business+ means the permission is available on Business and Enterprise plans. Enterprise means it requires the Enterprise plan.

Some permissions automatically include others. When you select a parent permission, all child permissions are included:

  • Edit queries includes View queries.
  • Use Assist with Build and Ask mode includes Use Assist with Ask mode only.
  • Manage billing includes Manage user seats.

The UI automatically handles these dependencies when you configure roles.

Organization permissions

Organization permission scopes control access to administrative settings pages.

User management

PermissionDescriptionPlan
Manage single sign-on (SSO)Configure single sign-on integrations.Enterprise
Manage user attributesDefine and manage custom user attributes.Enterprise
View account detailsView and manage account details.Business+
View users page with emailsView the users page with user emails.Business+
Example

Create an Identity Manager role for your IT team to manage SSO and user provisioning without full admin access.

Query library

PermissionDescriptionPlan
Edit queriesCreate, edit, and delete queries in the library.Business+
View queriesView and use queries from the library.Business+
Example

Create a Query Developer role for database experts to manage shared query templates.

Organization configuration

PermissionDescriptionPlan
Manage SpacesConfigure and manage Spaces.Enterprise
Manage internationalizationConfigure language and localization settings.Enterprise
Manage Retool APIManage API access tokens and settings.Enterprise
Manage source controlConfigure Git integrations.Enterprise
Manage usage analyticsView and configure analytics.Business+
Manage billingView and manage billing settings.Enterprise
Manage user seatsAssign and modify user seat types (builder, internal, or external).Enterprise
View audit logsAccess audit log data.Business+
Example

Create a Finance Admin role that grants access to billing and usage analytics only, allowing your finance team to monitor costs without accessing other settings.

Customization

PermissionDescriptionPlan
Manage brandingConfigure organization branding and styling.Enterprise
Manage themesCreate and edit custom themes.Business+
Manage Retool EventsConfigure and manage Retool Events.Enterprise
Manage Retool ExternalConfigure external user access and APIs.Enterprise
Manage custom components librariesManage custom component libraries.Enterprise
Example

Create a Design Manager role for your design team to manage branding and themes.

Configuration

PermissionDescriptionPlan
Allow access to unpublished releasesGrant access to edge/unpublished releases.Business+
Manage environmentsConfigure resource environments.Enterprise
Manage configuration variablesManage config variables.Enterprise
Manage Retool AIConfigure AI features and settings.Enterprise
Manage IAM credentialsManage secrets and IAM integrations.Enterprise
Manage observabilityConfigure monitoring and observability.Enterprise
Example

Create a DevOps Manager role that grants access to environments, config variables, and IAM credentials for your operations team.

Additional settings

PermissionDescriptionPlan
Manage advanced settingsAccess advanced organization settings.Enterprise
Manage mobile settingsConfigure mobile app settings.Enterprise
Manage beta settingsAccess and configure beta features.Enterprise
Manage draft appsControl draft app access and settings.Business+

Assist

PermissionDescriptionPlan
Use Assist with Build and Ask modeFull write access to Assist features.Business+
Use Assist with Ask mode onlyRead-only access to Assist features.Business+
Example

Create an Assist Editor role to allow specific teams to configure AI assistance for their users.

Object permissions

The object permissions feature is currently rolling out to cloud instances. It is not yet available on self-hosted instances.

Object permission scopes let you use roles to grant access to Retool objects (apps, resources, workflows, and agents) rather than just organization settings. These scopes appear as a Universal object permissions category in the role editor and are available on the Enterprise plan.

Universal object permissions grant access to all objects of a given type across the organization.

Apps

PermissionDescriptionPlan
View all appsGrant Use access to all apps.Enterprise
Edit all appsGrant Edit access to all apps.Enterprise
Own all appsGrant Own access to all apps.Enterprise

Resources

PermissionDescriptionPlan
View all resourcesGrant Use access to all resources.Enterprise
Edit all resourcesGrant Edit access to all resources.Enterprise
Own all resourcesGrant Own access to all resources.Enterprise

Workflows

PermissionDescriptionPlan
View all workflowsGrant Use access to all workflows.Enterprise
Edit all workflowsGrant Edit access to all workflows.Enterprise
Own all workflowsGrant Own access to all workflows.Enterprise

Agents

PermissionDescriptionPlan
View all agentsGrant Use access to all agents.Enterprise
Edit all agentsGrant Edit access to all agents.Enterprise
Own all agentsGrant Own access to all agents.Enterprise
Example

Create a Resource Administrator role with Own all resources to allow a platform team to manage all data connections without granting full admin access.

Updated app builder

Permission nameDescriptionBusinessEnterprise
Build apps in the AI-powered app builderControl access to the updated app builder.
Example

Create a New App Builder role to allow specific teams to access the AI-powered app builder.