# Understanding Member roles

## Understanding Member roles

A Member can be a colleague or someone outside your team, and their role decides what they can reach. Here are the built-in roles.

## Compare the built-in roles

Open Members, then Roles. Five roles are built in: Manager, Platform Support, User, Agent, and External. The role you choose sets what that Member can reach.

## Manager

Manager carries every workspace permission — seventy-two scopes, including the administrative ones. It is the role for the people running the workspace. General holds those permissions; the other tabs set which Workflows, Sites and Forms the role can reach.

## Platform Support

Platform Support mirrors Manager, but it is a separate role reserved for Gravity Rail's support team, so their authorized access is transparent and auditable. Workspace operators do not assign it.

## User

User is limited participation: four scopes. It can read Agents and read and write direct messages — enough to message your Agent, without managing the workspace.

## External

External is the restricted role for people outside your team, such as patients. It grants no workspace permissions. External Members reach only their own Assignments and Chats.

## Agent

Agent is for AI agents acting on their own, without a person in the loop. It grants no role permissions; an agent acts only through the tools and scope checks you configure for it.

## Choose access with Member roles

Choose the role that matches the access each person needs. You can also define role-based access to individual Workflows, Sites and Forms. Find the steps at docs.gravityrail.com.
