Source: https://atomic-works-test.docs-staging.pageloop.ai/product/ai-workforce/workforce-roles-and-permissions

# Workforce roles and permissions

Workforce roles let you decide who can view, build, and manage AI Coworkers — one workspace at a time. Instead of making someone an organization admin just so they can work on coworkers, you can grant the exact level of access they need in the workspaces they own.

> [!NOTE]
>
> Workforce roles are rolling out gradually. If you don't see them in your account yet, reach out to your Atomicwork contact.

## The three Workforce roles

There are three Workforce roles. Each one builds on the one before it — a Creator can do everything an Analyst can, and an Admin can do everything a Creator can (Analyst ⊂ Creator ⊂ Admin).

- **AI Workforce Analyst** — view-only access. See the coworkers in the workspace, their skills and tools, and the AI Workforce dashboard. An Analyst can't make changes. This suits team leads and stakeholders who need visibility without the ability to edit.

- **AI Workforce Creator** — everything an Analyst can do, plus build and operate coworkers: create and manage coworkers, edit their skills, tools, and code, create and manage evaluations, view runs and evaluation results, and take over or stop a running coworker.

- **AI Workforce Admin** — everything a Creator can do, plus manage the coworker budget for the workspace.

## What each role can do

| Capability                           | Analyst | Creator | Admin |
| ------------------------------------ | :-----: | :-----: | :---: |
| View coworkers, skills, and tools    |    ✓    |    ✓    |   ✓   |
| View the AI Workforce dashboard      |    ✓    |    ✓    |   ✓   |
| View coworker runs and evaluations   |    —    |    ✓    |   ✓   |
| Create and manage coworkers          |    —    |    ✓    |   ✓   |
| Manage skills, tools, and code       |    —    |    ✓    |   ✓   |
| Create and manage evaluations        |    —    |    ✓    |   ✓   |
| Take over or stop a running coworker |    —    |    ✓    |   ✓   |
| Manage the coworker budget           |    —    |    —    |   ✓   |

## Roles apply per workspace

Workforce roles are scoped to a workspace. A role you assign in one workspace grants access only there — someone can be an **AI Workforce Creator** in your IT workspace and have no coworker access in HR or Finance. This lets each team run its own coworkers without seeing or touching another team's.

Organization admins are unchanged: they continue to have access to AI Coworkers across every workspace.

## Assigning a Workforce role

Workforce roles are assigned like any other workspace role, so only workspace admins and organization admins can grant them.

- Go to **Settings > Your workspace > Users**.

- Add a user, or edit an existing one, and choose the Workforce role you want to give them.

- Save. The user gets that level of access to AI Coworkers in this workspace only. To grant access in another workspace, assign the role there too.

## Related

- [Setting up an AI Coworker](/product/ai-workforce/setting-up-an-ai-coworker)
- [Understanding how AI Coworkers run](/product/ai-workforce/understanding-how-ai-coworkers-run)
- [Roles in Atomicwork](/product/identity-access/people-roles-and-teams/roles-in-atomicwork)
