docs/v1.10.0/en/enterprise/features/rbac.mdx
RBAC in CrewAI AMP enables secure, scalable access management through a combination of organization‑level roles and automation‑level visibility controls.
<Frame> </Frame>Each member in your CrewAI workspace is assigned a role, which determines their access across various features.
You can:
You can configure users and roles in Settings → Roles.
<Steps> <Step title="Open Roles settings"> Go to <b>Settings → Roles</b> in CrewAI AMP. </Step> <Step title="Choose a role type"> Use a predefined role (<b>Owner</b>, <b>Member</b>) or click{" "} <b>Create role</b> to define a custom one. </Step> <Step title="Assign to members"> Select users and assign the role. You can change this anytime. </Step> </Steps>| Area | Where to configure | Options |
|---|---|---|
| Users & Roles | Settings → Roles | Predefined: Owner, Member; Custom roles |
| Automation visibility | Automation → Settings → Visibility | Private; Whitelist users/roles |
In addition to organization‑wide roles, CrewAI Automations support fine‑grained visibility settings that let you restrict access to specific automations by user or role.
This is useful for:
Deployments can be configured as private, meaning only whitelisted users and roles will be able to:
The organization owner always has access, regardless of visibility settings.
You can configure automation‑level access control in Automation → Settings → Visibility tab.
<Steps> <Step title="Open Visibility tab"> Navigate to <b>Automation → Settings → Visibility</b>. </Step> <Step title="Set visibility"> Choose <b>Private</b> to restrict access. The organization owner always retains access. </Step> <Step title="Whitelist access"> Add specific users and roles allowed to view, run, and access logs/metrics/settings. </Step> <Step title="Save and verify"> Save changes, then confirm that non‑whitelisted users cannot view or run the automation. </Step> </Steps>| Action | Owner | Whitelisted user/role | Not whitelisted |
|---|---|---|---|
| View automation | ✓ | ✓ | ✗ |
| Run automation/API | ✓ | ✓ | ✗ |
| Access logs/metrics/settings | ✓ | ✓ | ✗ |