DevJock.aiDevJock.ai
Account and Administration

Roles and Permissions (RBAC)

How workspace-scoped roles control what members, agents, and skills can do in DevJock.

Access control in DevJock is scoped by workspace. A workspace is the top of the brain's hierarchy, holding its projects, sprints, epics, tasks, memories, and files. Membership and roles are granted per workspace, so a person can have one level of access in one workspace and a different level in another.

Roles are per workspace

A role determines what a member can do inside a single workspace: what they can read, create, edit, and manage. Roles are granted within a workspace rather than across all of them, so access does not automatically carry from one workspace to another. Adding someone to a workspace grants them the role you assign there, and removing them from a workspace revokes that access without affecting their access elsewhere.

The practical unit of access control is therefore the workspace boundary. If you need a group of people to see and act on a set of tasks, put that work in a shared workspace and grant the right roles there. If work should stay separate, keep it in its own workspace.

Agent and skill access is also workspace-scoped

The same boundary applies to the agentic layer. Agents and skills are made available within a workspace, so the agents that can run and the skills they can use are governed by the same workspace membership and roles that govern people. An agent operating in a workspace acts within that workspace's scope, and its access to tasks, memories, and files follows the workspace it is working in.

This keeps the human side and the agent side consistent: whoever or whatever is working in a workspace is bounded by that workspace.

Managing access

Workspace membership and roles are managed from the workspace settings in the app, and organization-level membership is managed under the Account area in My Organizations. Assign members to the workspaces they need, choose the appropriate role for each, and review membership when responsibilities change.

Grant access at the workspace level. To broaden or restrict what someone or an agent can do, change their role in the relevant workspace or move the work into a workspace with the access you want.

On this page