Documentation for automated readers
A curated documentation index is available at: https://grafana.com/llms.txt
A complete documentation index is available at: https://grafana.com/llms-full.txt
These indexes can help with page discovery before fetching individual documents.
This page is also available in Markdown, which may be easier for automated readers and AI tools to parse than HTML. The Markdown version is available at https://grafana.com/docs/grafana-cloud/machine-learning/assistant/privacy-and-security/rbac.md, or by sending Accept: text/markdown to https://grafana.com/docs/grafana-cloud/machine-learning/assistant/privacy-and-security/rbac/. For broader documentation discovery, the curated index is available at https://grafana.com/llms.txt and the complete index is available at https://grafana.com/llms-full.txt.
Manage Assistant access with RBAC
Grafana Assistant relies on Grafana role-based access control (RBAC) so you can decide who can chat, run investigations, or administer deployment-wide settings. This article explains the roles available, the permissions they unlock, and how to grant users the access they need.
Before you begin
Decide who needs chat access, admin access, or investigation access before you start assigning roles.
- Organization administrator access: Only admins can assign Assistant-related roles and permissions.
- RBAC plan: Decide which teams need chat, investigations, or administrative control. For planning guidance, refer to Plan your Grafana RBAC rollout strategy.
- Feature availability: Confirm Assistant is available or enabled in your stack. Investigations require a separate entitlement.
- Scope per deployment: Assistant uses Grafana RBAC in the Grafana deployment where the plugin runs. In Grafana Cloud, that means a Grafana Cloud stack. In self-managed Grafana, that means your local Grafana instance. Use
plugins.app:accessscoped toplugins:id:grafana-assistant-appto control who can open Assistant. To remove or disable Assistant in a deployment, use the controls available in your stack. Where plugin settings expose enablement controls, an administrator can navigate to Administration > Plugins and data > Plugins, search for Grafana Assistant or go directly to/plugins/grafana-assistant-app, clear the agreement checkbox or the Assistant enabled or Enable Assistant checkbox, and click Save.
Note
In self-managed Grafana, the self-managed deployment hides some Grafana Cloud-dependent features entirely. RBAC still governs access to the Assistant app and its remaining settings, but permissions alone do not enable investigations, MCP management, SQL discovery, or automations in a self-managed deployment.
Understand available roles
Grafana offers baseline organization roles plus Assistant-specific roles. Combining them lets you tailor access without granting more privileges than necessary.
Organization roles define broad access in Grafana:
| Organization role | What the role can do with Grafana Assistant |
|---|---|
| Admin | Full access to Assistant chat, investigations, rules, and MCP server management. |
| Editor | Chat, CLI access, investigations, personal MCP server management, and read-only GitHub App settings. |
| Viewer | Chat access. |
| No basic role | No Assistant access unless an administrator adds an Assistant-specific role. |
Tip
To limit Assistant access for users who hold a Viewer or Editor organization role, an administrator can update the basic role with the RBAC API and remove specific permissions. For example, remove
plugins.app:accessscoped toplugins:id:grafana-assistant-appor removegrafana-assistant-app.chats:accessfrom the Viewer role.
Assistant-specific roles extend or restrict access regardless of the user’s organization role:
| Assistant role | What the role unlocks |
|---|---|
| Assistant Admin | Administers deployment-wide Assistant settings, usage analytics and limits, rules, MCP servers, automations, and investigations in addition to chat. |
| Assistant Cloud MCP User | Authorizes and manages external AI agent connections to Grafana via the Grafana Cloud MCP server. |
| Assistant MCP User | Uses Assistant chat, manages personal MCP servers and rules, and views GitHub App settings. |
| Assistant User | Basic Assistant chat plus personal rule management and personal skills. |
| Assistant CLI User | Authenticates and uses the Grafana Assistant CLI. Grants grafana-assistant-app.tokens:access. Automatically assigned to users with the Editor organization role or above. |
| Assistant Investigation User | Launches and manages Assistant investigations. |
| Assistant System Investigation Viewer | Adds visibility of system-created investigations. Combine with Assistant Investigation User or organization Admin. |
| gcx User | Authorizes GCX CLI connections to Grafana. Granted to the Viewer role by default so any logged-in user can run gcx login. |
Assign Assistant-specific roles to give targeted access to teammates who are not Editors or Admins.
Note
System-created investigations (launched automatically via IRM webhooks, alerts, or incidents) are hidden by default. Only users with the Assistant System Investigation Viewer role (combined with Assistant Investigation User) or organization Admin role can see them.
Grant access in Grafana
Use the following procedures to grant the right level of access without over-provisioning.
Grant basic Assistant chat access
- Sign in as an organization administrator.
- Go to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant User.
- Click Apply.
Grant CLI access
Users with the Editor organization role or above receive the Assistant CLI User role automatically. To grant CLI access to a user without the Editor role:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant CLI User.
- Click Apply.
Allow users to launch investigations and skills
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Investigation User.
- Click Apply.
Allow users to view system-created investigations
System-created investigations are launched automatically by IRM webhooks, alerts, or incidents. By default, only organization Admins can view them. This role is additive — the user also needs the Assistant Investigation User role for general investigation access.
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Investigation User (if not already assigned).
- Also choose Assistant > Assistant System Investigation Viewer.
- Click Apply.
Delegate Assistant administration
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Admin.
- Click Apply.
Users can hold multiple Assistant roles if they need both investigation access and deployment-wide configuration control.
Control access to Automations
Automations use scoped permissions for normal access and explicit tenant-wide permissions for administration.
| Permission | Access |
|---|---|
grafana-assistant-app.automations.user:read | View personal automations owned by the caller. |
grafana-assistant-app.automations.user:create | Create and manually run personal automations owned by the caller. |
grafana-assistant-app.automations.user:write | Edit, enable, and disable personal automations owned by the caller. |
grafana-assistant-app.automations.user:delete | Delete personal automations owned by the caller. |
grafana-assistant-app.automations.tenant:read | View automations shared with everybody in the stack. |
grafana-assistant-app.automations.tenant:create | Create and manually run automations shared with everybody in the stack. |
grafana-assistant-app.automations.tenant:write | Edit, enable, and disable automations shared with everybody in the stack. |
grafana-assistant-app.automations.tenant:delete | Delete automations shared with everybody in the stack. |
grafana-assistant-app.automations:read | View every automation in the stack, including another user’s private automation. |
grafana-assistant-app.automations:write | Edit any automation, including its enabled state and visibility. |
The Assistant Admin role includes both tenant-wide permissions and all scoped automation permissions. Tenant-wide read and write don’t expose another user’s private run history or grant permission to run or delete that user’s private automation. The UI labels these automations Private, shows their creator, and records the last editor when an administrator changes one.
Control access to Skills
Skills use separate permissions for personal and deployment-wide scope.
Users with Assistant User can create, edit, and delete their own Just me skills. Users with Assistant Admin can also create, edit, and delete Everybody skills for the deployment. Users who don’t have deployment-wide skill permissions can still view shared skills, but they can’t modify them.
Control access to Usage Analytics and limits
The Assistant > Usage page is gated by the grafana-assistant-app.usage:read permission. Editing limits from that page requires grafana-assistant-app.usage:write.
By default, these permissions are included in the Assistant Admin role. The Assistant Admin role is granted to the organization Admin basic role by default.
Enable Grafana Cloud MCP access
Grafana Cloud MCP access is automatically included for users with the Editor role or higher. To grant Grafana Cloud MCP access to users without the Editor role:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Cloud MCP User.
- Click Apply.
To allow users to authorize write-scoped Grafana Cloud MCP connections (enabling tools that create or modify resources), add the Assistant Admin role.
For more information, refer to Grafana Cloud MCP server.
Enable MCP server management
To allow users to configure personal MCP servers without granting full Editor access:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant MCP User.
- Click Apply.
MCP servers configured with Everybody scope require deployment-wide MCP permissions, typically the Grafana Admin basic role or Assistant Admin.
Understand memory access control
Assistant respects Grafana’s existing RBAC when accessing memories:
- Dashboard memory: Search results are filtered based on your Grafana folder and dashboard permissions. You can only discover and reference dashboards you have access to view.
- Infrastructure memory: Semantic search results are filtered by datasource permissions. You can only access infrastructure metrics from datasources you’re authorized to query. If permissions can’t be verified, access is denied by default.
This ensures Assistant never exposes data beyond your existing Grafana permissions.
Map permissions to actions
Each Assistant role grants a set of permissions. Use the tables below when you need to understand or audit the underlying RBAC settings.
Core permissions
| Permission | Description | Scope |
|---|---|---|
plugins.app:access | Access the Assistant plugin shell. | plugins:id:grafana-assistant-app |
grafana-assistant-app.settings.terms:write | Manage Assistant enablement and terms settings. | n/a |
grafana-assistant-app.settings.sql-discovery:read | Read SQL table discovery settings. | n/a |
grafana-assistant-app.settings.sql-discovery:write | Configure SQL table discovery settings. | n/a |
grafana-assistant-app.settings.analyst:read | Read Analyst mode data warehouse settings. | n/a |
grafana-assistant-app.settings.analyst:write | Configure the Analyst mode data warehouse datasource. | n/a |
grafana-assistant-app.settings.investigations:read | Read tenant investigation settings (alert continuation, loops). | n/a |
grafana-assistant-app.settings.investigations:write | Configure tenant investigation settings, including alert continuation and the tenant-wide loops toggle. | n/a |
grafana-assistant-app.chats:access | Use Assistant chat. | n/a |
grafana-assistant-app.tokens:access | Authenticate with the Grafana Assistant CLI. | n/a |
grafana-assistant-app.rules.user:read | Read personal Assistant rules. | n/a |
grafana-assistant-app.rules.user:create | Create personal Assistant rules. | n/a |
grafana-assistant-app.rules.user:write | Update personal Assistant rules. | n/a |
grafana-assistant-app.rules.user:delete | Delete personal Assistant rules. | n/a |
grafana-assistant-app.rules.tenant:read | Read tenant-level Assistant rules. | n/a |
grafana-assistant-app.rules.tenant:create | Create tenant-level Assistant rules. | n/a |
grafana-assistant-app.rules.tenant:write | Update tenant-level Assistant rules. | n/a |
grafana-assistant-app.rules.tenant:delete | Delete tenant-level Assistant rules. | n/a |
grafana-assistant-app.mcps.user:read | Read personal MCP servers. | n/a |
grafana-assistant-app.mcps.user:create | Create personal MCP servers. | n/a |
grafana-assistant-app.mcps.user:write | Update personal MCP servers. | n/a |
grafana-assistant-app.mcps.user:delete | Delete personal MCP servers. | n/a |
grafana-assistant-app.mcps.tenant:read | Read tenant MCP servers. | n/a |
grafana-assistant-app.mcps.tenant:create | Create tenant MCP servers. | n/a |
grafana-assistant-app.mcps.tenant:write | Update tenant MCP servers. | n/a |
grafana-assistant-app.mcps.tenant:delete | Delete tenant MCP servers. | n/a |
grafana-assistant-app.github:read | Read GitHub App connection and repository access settings. | n/a |
grafana-assistant-app.github:write | Configure GitHub App connection and repository access settings. | n/a |
grafana-assistant-app.investigations:read | View investigations. | n/a |
grafana-assistant-app.investigations:create | Launch investigations. | n/a |
grafana-assistant-app.investigations.system:read | View system-created investigations. | n/a |
grafana-assistant-app.cloud-mcp:access | Connect external AI agents via Grafana Cloud MCP and manage connections. | n/a |
grafana-assistant-app.cloud-mcp.scope:write | Authorize Grafana Cloud MCP connections with write scope. | n/a |
grafana-assistant-app.skills.user:* | Manage personal skills. | n/a |
grafana-assistant-app.skills.tenant:* | Manage deployment-wide shared skills. | n/a |
grafana-assistant-app.automations.user:read | View personal automations owned by the caller. | n/a |
grafana-assistant-app.automations.user:create | Create or manually run personal automations owned by the caller. | n/a |
grafana-assistant-app.automations.user:write | Edit, enable, or disable personal automations owned by the caller. | n/a |
grafana-assistant-app.automations.user:delete | Delete personal automations owned by the caller. | n/a |
grafana-assistant-app.automations.tenant:read | View automations shared with everybody in the stack. | n/a |
grafana-assistant-app.automations.tenant:create | Create or manually run automations shared with everybody in the stack. | n/a |
grafana-assistant-app.automations.tenant:write | Edit, enable, or disable automations shared with everybody in the stack. | n/a |
grafana-assistant-app.automations.tenant:delete | Delete automations shared with everybody in the stack. | n/a |
grafana-assistant-app.automations:read | View every automation in the stack, including private automations. | n/a |
grafana-assistant-app.automations:write | Update every automation in the stack, including private automations. | n/a |
grafana-assistant-app.usage:read | View Usage Analytics for the deployment. | n/a |
grafana-assistant-app.usage:write | Update deployment usage limits. | n/a |
grafana-assistant-app.tokens.gcx:access | Authorize a GCX CLI connection to Grafana (gcx login). Granted to Viewer by default. | n/a |
Actions and required permissions
| Assistant action | Required permissions (all) |
|---|---|
| Enable Assistant or manage terms | grafana-assistant-app.settings.terms:write, plugins.app:access |
| Configure SQL table discovery | grafana-assistant-app.settings.sql-discovery:write, grafana-assistant-app.settings.sql-discovery:read, plugins.app:access |
| Configure Analyst data warehouse | grafana-assistant-app.settings.analyst:write, grafana-assistant-app.settings.analyst:read, plugins.app:access |
| Configure investigation settings | grafana-assistant-app.settings.investigations:write, grafana-assistant-app.settings.investigations:read, plugins.app:access |
| Use Assistant chat | grafana-assistant-app.chats:access, plugins.app:access |
| Authenticate with the CLI | grafana-assistant-app.tokens:access, plugins.app:access |
| Manage personal rules | grafana-assistant-app.rules.user:*, grafana-assistant-app.chats:access, plugins.app:access |
| Manage personal MCP servers | grafana-assistant-app.mcps.user:*, grafana-assistant-app.chats:access, plugins.app:access |
| Manage tenant rules | grafana-assistant-app.rules.tenant:*, grafana-assistant-app.chats:access, plugins.app:access |
| Manage tenant MCP servers | grafana-assistant-app.mcps.tenant:*, grafana-assistant-app.chats:access, plugins.app:access |
| View GitHub App access | grafana-assistant-app.github:read, plugins.app:access |
| Configure GitHub App access | grafana-assistant-app.github:write, grafana-assistant-app.github:read, plugins.app:access |
| Use investigations | grafana-assistant-app.investigations:*, grafana-assistant-app.chats:access, plugins.app:access |
| View system-created investigations | grafana-assistant-app.investigations.system:read, grafana-assistant-app.investigations:read, plugins.app:access |
| Manage personal skills | grafana-assistant-app.skills.user:*, grafana-assistant-app.chats:access, plugins.app:access |
| Manage tenant-wide skills | grafana-assistant-app.skills.tenant:*, grafana-assistant-app.chats:access, plugins.app:access |
| View personal automations | grafana-assistant-app.automations.user:read, plugins.app:access |
| Create or manually run personal automations | grafana-assistant-app.automations.user:create, plugins.app:access |
| Edit, enable, or disable personal automations | grafana-assistant-app.automations.user:write, plugins.app:access |
| Delete personal automations | grafana-assistant-app.automations.user:delete, plugins.app:access |
| View automations shared with everybody | grafana-assistant-app.automations.tenant:read, plugins.app:access |
| Create or manually run shared automations | grafana-assistant-app.automations.tenant:create, plugins.app:access |
| Edit, enable, or disable shared automations | grafana-assistant-app.automations.tenant:write, plugins.app:access |
| Delete automations shared with everybody | grafana-assistant-app.automations.tenant:delete, plugins.app:access |
| View and edit every automation | grafana-assistant-app.automations:read, grafana-assistant-app.automations:write, plugins.app:access |
| View Usage Analytics dashboard | grafana-assistant-app.usage:read, plugins.app:access |
| Configure usage limits | grafana-assistant-app.usage:write, grafana-assistant-app.usage:read, plugins.app:access |
| Connect via Grafana Cloud MCP | grafana-assistant-app.cloud-mcp:access, plugins.app:access |
| Authorize write-scoped Grafana Cloud MCP connections | grafana-assistant-app.cloud-mcp.scope:write, grafana-assistant-app.cloud-mcp:access, plugins.app:access |
Authorize a GCX CLI connection (gcx login) | grafana-assistant-app.tokens.gcx:access, plugins.app:access |
Permissions with a * suffix mean the role needs read, create, write, and delete access for that feature area.
Next steps
- Review Manage your data privacy and security to understand data handling, third-party providers, security measures, and access controls.
- Review Pricing and limits to understand projected costs and limits.
Was this page helpful?
Related resources from Grafana Labs


