What It Is
PANTA OS handles permissions through roles. The key points at a glance:- There are three fixed system roles: User, Team Lead, and Admin.
- Every user has exactly one role; it applies across the entire workspace.
- The role determines which areas of the platform are visible and which administrative tasks a user can take on.
- In addition, Administrators can create Custom Roles with granularly configurable permissions and assign them to users.
- The three system roles remain untouched: they can neither be edited nor deleted.
The Three System Roles
User
The default role for all members. Users work with chats, assistants, and apps, create personal assistants, read the community feed, and authorize their personal integrations.
Team Lead
Sits between User and Admin. Team Leads take on day to day team management: managing users, creating and editing teams, publishing posts to the community feed. Without full administrative access to the workspace.
Admin
Full control over the workspace: tenant integrations, branding, logo and system prompt, token limits, and analytics, on top of all Team Lead rights.
Team Leads see the Admin area in the sidebar, but with a reduced view:
- Visible: only the Teams tab
- Not visible: Analytics, Users, Integrations, Community Feed, Organization Settings, and Token Limits (reserved for Administrators)
Permissions at a Glance
Custom Roles
Administrators can create their own roles with configurable permissions to match the structure of the organization. In short:- Only Administrators create, edit, and delete Custom Roles.
- Each role gets a unique name and individually enabled permissions.
- Custom Roles are assigned to users throughout the organization.
- The system roles User, Team Lead, and Admin are exempt: fixed, not editable, not deletable.
Create a role
In the Admin Panel under Users, you will find the Custom Roles section. Create New Role opens the dialog to create a new role with a unique name.
Configure permissions
Each permission is enabled or disabled individually with a toggle. The result is a role that covers exactly the capabilities needed, no more and no less.
Assign roles
Custom roles are assigned to users throughout the organization, matching each area of responsibility.
System roles stay fixed
User, Team Lead, and Admin are not configurable and cannot be deleted. This protects core platform integrity and a consistent baseline experience.
Assistant Visibility
Independent of the user role, there are two visibility levels for assistants:- Private: Visible only to the creator.
- Public: Visible across the entire workspace. Public assistants can be assigned to specific teams through Team Management; members of those teams then see them in their dashboard.
Tips and Best Practices
- Start with the system roles. Custom roles are worth it only when no system role cleanly covers an area of responsibility.
- Appoint one Team Lead per team. This distributes day to day administrative work without handing out full admin rights.
- Keep the number of custom roles small. A few clearly named roles are easier to maintain than many special cases.
- For every custom role, check whether all enabled permissions are really needed.
Help Center
Who can change roles
Who can change roles
Only Administrators assign or change roles, in the Admin Panel under Users. Team Leads manage users and teams but do not assign roles.
What does a Team Lead see in the Admin Panel
What does a Team Lead see in the Admin Panel
Only the Teams tab. Analytics, Users, Integrations, Community Feed, Organization Settings, and Token Limits are not visible to Team Leads.
Can I customize the system roles
Can I customize the system roles
No. User, Team Lead, and Admin are fixed and can neither be edited nor deleted. Custom roles exist for any differing permission combinations.
Are there team-specific roles
Are there team-specific roles
Roles apply across the entire workspace, not per team. A Team Lead can create and edit teams throughout the workspace.
How does an assistant reach exactly one team
How does an assistant reach exactly one team
Set the assistant to Public and assign it to the desired team in Team Management. Only members of that team will then see it in their dashboard.
