Admin permissions reference
Reference of all organization-level permissions available in Retool roles.
Organization roles grant access to organization-wide settings. Object roles grant access to apps, resources, workflows, and agents. Both are configured from Settings > Roles & Permissions.
The Plan column shows the minimum plan required to use each permission. Business+ means the permission is available on Business and Enterprise plans. Enterprise means it requires the Enterprise plan.
Some permissions automatically include others. When you select a parent permission, all child permissions are included:
- Edit queries includes View queries.
- Use Assist with Build and Ask mode includes Use Assist with Ask mode only.
- Manage billing includes Manage user seats.
The UI automatically handles these dependencies when you configure roles.
Organization permissions
Organization permission scopes control access to administrative settings pages.
User management
| Permission | Description | Plan |
|---|---|---|
| Manage single sign-on (SSO) | Configure single sign-on integrations. | Enterprise |
| Manage user attributes | Define and manage custom user attributes. | Enterprise |
| View account details | View and manage account details. | Business+ |
| View users page with emails | View the users page with user emails. | Business+ |
Example
Create an Identity Manager role for your IT team to manage SSO and user provisioning without full admin access.
Query library
| Permission | Description | Plan |
|---|---|---|
| Edit queries | Create, edit, and delete queries in the library. | Business+ |
| View queries | View and use queries from the library. | Business+ |
Example
Create a Query Developer role for database experts to manage shared query templates.
Organization configuration
| Permission | Description | Plan |
|---|---|---|
| Manage Spaces | Configure and manage Spaces. | Enterprise |
| Manage internationalization | Configure language and localization settings. | Enterprise |
| Manage Retool API | Manage API access tokens and settings. | Enterprise |
| Manage source control | Configure Git integrations. | Enterprise |
| Manage usage analytics | View and configure analytics. | Business+ |
| Manage billing | View and manage billing settings. | Enterprise |
| Manage user seats | Assign and modify user seat types (builder, internal, or external). | Enterprise |
| View audit logs | Access audit log data. | Business+ |
Example
Create a Finance Admin role that grants access to billing and usage analytics only, allowing your finance team to monitor costs without accessing other settings.
Customization
| Permission | Description | Plan |
|---|---|---|
| Manage branding | Configure organization branding and styling. | Enterprise |
| Manage themes | Create and edit custom themes. | Business+ |
| Manage Retool Events | Configure and manage Retool Events. | Enterprise |
| Manage Retool External | Configure external user access and APIs. | Enterprise |
| Manage custom components libraries | Manage custom component libraries. | Enterprise |
Example
Create a Design Manager role for your design team to manage branding and themes.
Configuration
| Permission | Description | Plan |
|---|---|---|
| Allow access to unpublished releases | Grant access to edge/unpublished releases. | Business+ |
| Manage environments | Configure resource environments. | Enterprise |
| Manage configuration variables | Manage config variables. | Enterprise |
| Manage Retool AI | Configure AI features and settings. | Enterprise |
| Manage IAM credentials | Manage secrets and IAM integrations. | Enterprise |
| Manage observability | Configure monitoring and observability. | Enterprise |
Example
Create a DevOps Manager role that grants access to environments, config variables, and IAM credentials for your operations team.
Additional settings
| Permission | Description | Plan |
|---|---|---|
| Manage advanced settings | Access advanced organization settings. | Enterprise |
| Manage mobile settings | Configure mobile app settings. | Enterprise |
| Manage beta settings | Access and configure beta features. | Enterprise |
| Manage draft apps | Control draft app access and settings. | Business+ |
Assist
| Permission | Description | Plan |
|---|---|---|
| Use Assist with Build and Ask mode | Full write access to Assist features. | Business+ |
| Use Assist with Ask mode only | Read-only access to Assist features. | Business+ |
Example
Create an Assist Editor role to allow specific teams to configure AI assistance for their users.
Object permissions
The object permissions feature is currently rolling out to cloud instances. It is not yet available on self-hosted instances.
Object permission scopes let you use roles to grant access to Retool objects (apps, resources, workflows, and agents) rather than just organization settings. These scopes appear as a Universal object permissions category in the role editor and are available on the Enterprise plan.
Universal object permissions grant access to all objects of a given type across the organization.
Apps
| Permission | Description | Plan |
|---|---|---|
| View all apps | Grant Use access to all apps. | Enterprise |
| Edit all apps | Grant Edit access to all apps. | Enterprise |
| Own all apps | Grant Own access to all apps. | Enterprise |
Resources
| Permission | Description | Plan |
|---|---|---|
| View all resources | Grant Use access to all resources. | Enterprise |
| Edit all resources | Grant Edit access to all resources. | Enterprise |
| Own all resources | Grant Own access to all resources. | Enterprise |
Workflows
| Permission | Description | Plan |
|---|---|---|
| View all workflows | Grant Use access to all workflows. | Enterprise |
| Edit all workflows | Grant Edit access to all workflows. | Enterprise |
| Own all workflows | Grant Own access to all workflows. | Enterprise |
Agents
| Permission | Description | Plan |
|---|---|---|
| View all agents | Grant Use access to all agents. | Enterprise |
| Edit all agents | Grant Edit access to all agents. | Enterprise |
| Own all agents | Grant Own access to all agents. | Enterprise |
Example
Create a Resource Administrator role with Own all resources to allow a platform team to manage all data connections without granting full admin access.
Updated app builder
| Permission name | Description | Business | Enterprise |
|---|---|---|---|
| Build apps in the AI-powered app builder | Control access to the updated app builder. |
Example
Create a New App Builder role to allow specific teams to access the AI-powered app builder.