Manage Assistant access with RBAC
Grafana Assistant relies on Grafana role-based access control (RBAC) so you can decide who can chat, run investigations, or administer deployment-wide settings. This article explains the roles available, the permissions they unlock, and how to grant users the access they need.
Note
Grafana Cloud honors the permissions granted by basic, custom, and Assistant-specific roles. In self-managed Grafana, use the basic Viewer, Editor, and Admin organization roles unless you run Grafana Enterprise in a configuration that supports Assistant custom permissions. In other self-managed deployments, Assistant uses a compatibility fallback based on the user’s basic organization role: Viewers can access and read, Editors can also create, write, and delete non-administrative resources, and Admins receive administrative permissions. Custom and Assistant-specific roles can’t grant permissions beyond this fallback. Contact your Grafana account team to confirm whether your deployment supports Assistant custom permissions. The
plugins.app:accesspermission still controls access to the plugin, and self-managed deployments hide some Grafana Cloud-dependent features entirely.
Before you begin
Decide who needs chat access, admin access, or investigation access before you start assigning roles.
- Organization administrator access: Only admins can assign Assistant-related roles and permissions.
- RBAC plan: Decide which teams need chat, investigations, or administrative control. For planning guidance, refer to Plan your Grafana RBAC rollout strategy.
- Feature availability: Confirm Assistant is available or enabled in your stack. Investigations require a separate entitlement.
- Scope per deployment: Assistant uses Grafana RBAC in the Grafana deployment where the plugin runs. In self-managed Grafana Enterprise deployments that support Assistant custom permissions, permissions are resolved by that local Grafana instance, even when it isn’t reachable from the internet. Use
plugins.app:accessscoped toplugins:id:grafana-assistant-appto control who can open Assistant. To remove or disable Assistant in a deployment, use the controls available in your stack. Where plugin settings expose enablement controls, an administrator can navigate to Administration > Plugins and data > Plugins, search for Grafana Assistant or go directly to/plugins/grafana-assistant-app, clear the agreement checkbox or the Assistant enabled or Enable Assistant checkbox, and click Save.
Understand available roles
Grafana offers baseline organization roles plus Assistant-specific roles. Combining them lets you tailor access without granting more privileges than necessary.
Organization roles define broad access in Grafana:
Tip
To limit Assistant access for users who hold a Viewer or Editor organization role, an administrator can update the basic role with the RBAC API and remove specific permissions. For example, remove
plugins.app:accessscoped toplugins:id:grafana-assistant-appor removegrafana-assistant-app.chats:accessfrom the Viewer role.
Assistant-specific roles extend or restrict access regardless of the user’s organization role in Grafana Cloud. They also work in self-managed Grafana Enterprise deployments that support Assistant custom permissions:
Assign Assistant-specific roles to give targeted access to teammates who are not Editors or Admins in Grafana Cloud or in self-managed Grafana Enterprise deployments that support Assistant custom permissions.
Note
System-created investigations (launched automatically via IRM webhooks, alerts, or incidents) are hidden by default. Only users with the Assistant System Investigation Viewer role (combined with Assistant Investigation User) or organization Admin role can see them.
View sandbox secret metadata
Viewers can see the names, descriptions, environment variables, types, and destinations of Assistant sandbox secrets when the feature is enabled. Saved secret values cannot be viewed in settings.
The inventory requires grafana-assistant-app.sandbox-secrets.user:read for your personal secrets or grafana-assistant-app.sandbox-secrets.tenant:read for shared secrets. Assistant Coding User, Assistant Coding Maintainer, and Assistant Coding Admin include both actions. Grant the applicable scoped actions explicitly to custom roles that need to browse the inventory; no separate settings permission is required. Metadata read access grants neither mutation operations nor decryption.
Assistant Coding User includes create, write, and delete actions for the caller’s personal secrets. Assistant Coding Maintainer and Assistant Coding Admin also include those actions for shared secrets. No role permits access to another user’s personal secrets through Assistant. Global coding-settings write is not required. Creating, replacing, and deleting secrets still requires the corresponding Grafana Secrets permissions, which assigning a coding role alone does not grant.
Secret grants now belong to the coding roles rather than Assistant User, Assistant MCP User, or Assistant Admin. Default basic-role assignments retain access through their coding roles. For users assigned only one of the former general roles explicitly, assign the appropriate coding role or exact secret permissions to retain access.
Grant access in Grafana
Use the following procedures to grant the right level of access without over-provisioning.
If you use self-managed Grafana without support for Assistant custom permissions, grant Assistant access with the basic Viewer, Editor, or Admin organization roles and plugins.app:access. The Assistant-specific role procedures in this section apply to Grafana Cloud and to self-managed Grafana Enterprise deployments that support Assistant custom permissions.
Grant basic Assistant chat access
- Sign in as an organization administrator.
- Go to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant User.
- Click Apply.
Grant CLI access
Users with the Editor organization role or above receive the Assistant CLI User role automatically. To grant CLI access to a user without the Editor role:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant CLI User.
- Click Apply.
Allow users to launch investigations and skills
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Investigation User.
- Click Apply.
Allow users to view system-created investigations
System-created investigations are launched automatically by IRM webhooks, alerts, or incidents. By default, only organization Admins can view them. This role is additive — the user also needs the Assistant Investigation User role for general investigation access.
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Investigation User (if not already assigned).
- Also choose Assistant > Assistant System Investigation Viewer.
- Click Apply.
View coding agent settings
By default, Viewers, Editors, and Admins can read coding agent settings. The
Assistant User and Assistant MCP User roles include
grafana-assistant-app.settings.coding-agents:read, so you can inspect the
configured providers and defaults without administrative access. This permission
does not expose credentials or grant access to the separate GitHub, Cursor, or
Claude integration settings.
Changing the deployment-wide coding policy requires
grafana-assistant-app.settings.coding-agents:write, included in Assistant Admin.
Reading the settings does not grant permission to enable or disable providers,
change their defaults, or manage sandbox secrets.
Control coding agent access
Assistant Coding User is granted to Viewer, Editor, and Admin by default. It permits coding execution and reading safe coding configuration. Coding must also be enabled for the tenant, and repository and user authorization still apply.
Coding Users can see every repository visible to the tenant’s GitHub App
installation, including private repository names, along with enrollment, network,
and automatic-publication settings. This extends GitHub settings visibility to
Viewers. It does not grant access to repository contents or bypass authorization
when running coding agents. Refreshing the repository inventory cache requires
Coding Maintainer or Coding Admin permissions. Environment build logs
require Coding Admin, or Coding Maintainer with GitHub write access to the
repository. grafana-assistant-app.github:read alone permits neither.
Assign Assistant Coding Maintainer explicitly to users or teams who manage repositories. Maintainers can configure repository enrollment, environments, network policy, reviews, mentions, and automatic pull requests using their linked GitHub account’s current write access. They also receive Assistant permissions to manage shared sandbox secrets, subject to Grafana Secrets permissions. They cannot connect GitHub installations, change global coding policy, or activate mentions globally.
Assistant Coding Admin, granted to Admin by default, manages global coding settings and integrations as well as repository configuration. These roles do not grant access to another user’s private conversations or credentials.
Connecting a GitHub App installation verifies ownership with the connecting
user’s linked GitHub account. Users with grafana-assistant-app.github:write can
link their own GitHub account without grafana-assistant-app.chats:access, so
Connect GitHub works for Coding Admins who can’t use Assistant chat. The same
permission lets them unlink their account.
To restrict coding while preserving chat, remove
grafana-assistant-app.coding:execute from the relevant basic-role permissions
and assign Coding User to the intended users or teams. Grafana permissions are
additive: removing one assignment does not revoke a permission still granted by
another role or team. Refer to Manage RBAC roles.
Fine-grained delegation requires Grafana Cloud or Enterprise RBAC. Self-managed
role fallback permits Viewer, Editor, and Admin to execute and reserves repository
configuration for Admin.
Disabling coding blocks new work and follow-ups, including queued starts. It does not cancel work that has already started. Settings show global editing controls only to users with the required permissions.
Repository-scoped secret delegation is a separate follow-up. The Coding Maintainer role does not currently grant secret management.
Delegate Assistant administration
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Admin.
- Click Apply.
Users can hold multiple Assistant roles if they need both investigation access and deployment-wide configuration control.
Control access to Investigations
Investigations use per-investigation visibility for normal access and an explicit tenant-wide permission for administration.
The Assistant Admin role includes grafana-assistant-app.investigations.all:read, which lets an administrator view every investigation in the stack, including another user’s private investigation and the chat that backs it. This permission grants read access only. It doesn’t let an administrator change an investigation’s team scope, pause or resume it, record hypothesis verdicts, or share it. Those actions still require the investigation’s creator or the appropriate role.
Control access to Automations
Automations use scoped permissions for normal access and explicit tenant-wide permissions for administration.
The Assistant Admin role includes both tenant-wide permissions and all scoped automation permissions. Creating or editing an automation that runs as the Assistant service account also requires the Grafana organization Admin role; Assistant Admin alone is insufficient. Such an automation must use Everybody visibility. Every invocation uses the existing Assistant tenant service account and the organization’s system-initiated token pool. Tenant-wide read and write don’t expose another user’s private run history or grant permission to run or delete that user’s private automation. The UI labels these automations Private, shows their creator, and records the last editor when an administrator changes one.
Control access to Skills
Skills use separate permissions for personal and deployment-wide scope.
Users with Assistant User can create, edit, and delete their own Just me skills. Users with Assistant Admin can also create, edit, and delete Everybody skills for the deployment. Users who don’t have deployment-wide skill permissions can still view shared skills, but they can’t modify them.
Control access to Usage Analytics and limits
The Assistant > Usage page is gated by the grafana-assistant-app.usage:read permission. Editing limits from that page requires grafana-assistant-app.usage:write.
By default, these permissions are included in the Assistant Admin role. The Assistant Admin role is granted to the organization Admin basic role by default.
Enable Grafana Cloud MCP access
Grafana Cloud MCP access is automatically included for users with the Editor role or higher. To grant Grafana Cloud MCP access to users without the Editor role:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant Cloud MCP User.
- Click Apply.
Grafana Cloud MCP connections come in three levels of access, and a user can only authorize a level they hold the permission for:
Query access lets a connection run queries against SQL data sources, for example, ClickHouse, Snowflake, Athena, and InfluxDB. These queries run as written, so a connection with query access can change data when the data source credentials allow it. Read access on its own doesn’t include these tools.
To allow users to authorize write-scoped Grafana Cloud MCP connections, which enable tools that create or modify resources, add the Assistant Admin role. Write access includes query access.
When an MCP client asks for access, the authorization page lists each level as a separate checkbox. Users can clear any level they don’t want to grant, and levels they can’t authorize appear unavailable.
For more information, refer to Grafana Cloud MCP server.
Enable MCP server management
To allow users to configure personal MCP servers without granting full Editor access:
- Sign in as an organization administrator.
- Navigate to Administration > Users and access > Users.
- Select the user and open the Role picker.
- Choose Assistant > Assistant MCP User.
- Click Apply.
MCP servers configured with Everybody scope require deployment-wide MCP permissions, typically the Grafana Admin basic role or Assistant Admin.
Sandbox secret permissions
When sandbox secrets are enabled, creating, editing, and deleting them requires a verified human identity, the exact Assistant action for the operation. Existing standalone records also require the corresponding Grafana Secrets Manager permissions:
Assistant Coding User includes both read actions and personal mutations. Assistant Coding Maintainer and Assistant Coding Admin include all eight actions. Custom roles that previously managed secrets using coding-settings write access must add the applicable secret actions. Organization-wide actions do not permit access to another user’s personal secrets through Assistant. Changing owner scope requires write access to both scopes. Repository selection restricts which sandbox runs receive a secret; it does not grant repository access. Authorized sandbox runs can use matching secrets without management permissions. Runs without a user identity receive only shared secrets.
Understand memory access control
Assistant respects Grafana’s existing RBAC when accessing memories:
- Dashboard memory: Search results are filtered based on your Grafana folder and dashboard permissions. You can only discover and reference dashboards you have access to view.
- Infrastructure memory: Semantic search results are filtered by datasource permissions. You can only access infrastructure metrics from datasources you’re authorized to query. If permissions can’t be verified, access is denied by default.
This ensures Assistant never exposes data beyond your existing Grafana permissions.
Map permissions to actions
Each Assistant role grants a set of permissions. Use the tables below when you need to understand or audit the underlying RBAC settings.
Core permissions
Actions and required permissions
Permissions with a * suffix mean the role needs read, create, write, and delete access for that feature area.
Next steps
- Review Manage your data privacy and security to understand data handling, third-party providers, security measures, and access controls.
- Review Pricing and limits to understand projected costs and limits.


