> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.moveworks.com/service-management/administration/manage-roles-and-permissions-for-moveworks-applications/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.moveworks.com/_mcp/server. # Roles and Permissions > **Info** > > ️ Pre-requisite: Please ask your single-sign on (SSO) Admin to follow [these instructions (link)](/service-management/administration/my-moveworks-overview) to configure Moveworks for your organization ([link](/service-management/administration/my-moveworks-overview)) and enable this application for you MyMoveworks is your one-stop portal to access all Moveworks applications. Within MyMoveworks there are a variety of applications (Moveworks Setup, Analytics, Agent Studio, Knowledge Studio, etc.) This guide will explain how to grant users access to specific applications. # Roles and Permissions for Administrators Moveworks provides Role-based Access Control (RBAC) capabilities for all Moveworks developed applications. As an administrator, learn to manage access to applications through the “Roles and Permissions” application in this section. There are three types of access you can configure for each user and application: * **Admin**: A role that can grant or revoke access to a specific licensed app for other users. * **Super Admin**: A role that can grant or revoke access to all licensed apps for other users. They can also grant or revoke admin access to applications. Moveworks Super Admin has the same access as the bot, bypassing any underlying system/data/API access controls. * **User**: A role that can access one app. They cannot add or remove access to these apps. Additionally, some applications like Agent Studio have additional roles controlling access to analytics for that particular application. You can access Roles and Permissions from your My Moveworks application through your single-sign on (SSO) app homepage or by logging into [https://my.moveworks.com](https://my.moveworks.com). ![](https://files.readme.io/19552cfa5fc494f42b377e5db93db52ca0413f37a517ef6a87746e8d3d415fe0-CleanShot_2025-04-30_at_10.11.26.png) \ **Don’t see Moveworks in your list of SSO applications?** You might not be a super admin or Moveworks app administrator. Request access from your organization's super admin or reach out to the Moveworks Customer Support Team. **Don’t see Moveworks in your list of SSO applications?** Check that your SSO admin has enabled the application for you. **Can’t log into[https://my.moveworks.com](https://my.moveworks.com) with your email?** Ensure your SSO admin has granted access to your desired email address. **Can’t log into[https://my.moveworks.com](https://my.moveworks.com) with your SSO admin?** Ask your SSO admin to Contact support to validate your SSO configuration with Moveworks. ## Standard Administrator and User Roles and Permissions \ > **Info** > > Important update: > > We are introducing a new role for Analytics. This role is aimed towards allowing admins to govern visibility of all user interactions with the assistant. Read more, on the community post below : > > > **Info** > > > > [https://community.moveworks.com/stakeholder%2Dtools%2Dexi%2Dmw%2Dsetup%2Dks%2Danalytics%2D115/product%2Dupdate%2Dnew%2Dinteractions%2Dviewer%2Drole%2Din%2Danalytics%2D2775?fid=115\&tid=2775](https://community.moveworks.com/stakeholder%2Dtools%2Dexi%2Dmw%2Dsetup%2Dks%2Danalytics%2D115/product%2Dupdate%2Dnew%2Dinteractions%2Dviewer%2Drole%2Din%2Danalytics%2D2775?fid=115\&tid=2775) Roles are grouped below by the product they apply to. Each table lists what the role can do and who typically holds it. Jump to a product: [Moveworks Setup](#moveworks-setup) · [Agent Studio](#agent-studio) · [Analytics](#analytics) · [Employee Communications](#employee-communications) · [Employee Experience Insights](#employee-experience-insights-exi) · [Knowledge Studio](#knowledge-studio) ### Roles across all products | Role | What it can do | Typically assigned to | | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------ | | **Super Administrator** | Grant or revoke access to any licensed Moveworks application, including admin access, and use any licensed application. Manages access to assistant analytics, Agent Studio, Employee Communications, Employee Experience Insights, and Knowledge Studio. Has the same access as the assistant, bypassing any underlying system, data, or API access controls. | Moveworks Product Owner Lead / Manager Project Manager | > **Note** > > Moveworks Setup permissions and Agent Studio log viewer roles are granted separately. Assign them explicitly, even for a Super Administrator. Agent Studio Admin also needs the log viewer roles to access run-time and sensitive webhook logs. ### Moveworks Setup | Role | What it can do | Typically assigned to | | ------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------- | | **Moveworks Setup Admin** | Configure all Moveworks products in every Moveworks Setup module, control connections to external platforms, manage stakeholder product configurations, and grant or revoke access to Moveworks Setup. | IT Lead / Manager Business Systems Administrator Senior IT Technician | | **Moveworks Setup User** | Configure Moveworks bot settings in every Moveworks Setup module, manage stakeholder product configurations, and control connections to external platforms. | Business App Product Owner IT Lead / Manager IT Project Manager Technical Knowledge Writer Senior IT Technician | | **Moveworks Setup PII Authorized Viewer (PII Viewer)** | See unredacted PII in Moveworks Setup troubleshooting surfaces: Chat Playback / Chat Evaluator, Ticket Viewer, and built-in plugin logs. Add-on, read-only role. Must be paired with Moveworks Setup User or Moveworks Setup Admin to take effect, and is not required for Super Administrators. | Designated Support Lead Compliance-Approved Investigator On-Call Incident Responder | ### Agent Studio | Role | What it can do | Typically assigned to | | ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | | **Agent Studio Admin** | Create custom conversational AI use cases, use API keys and connections to external platforms, view Agent Studio analytics, and grant or revoke access to use cases and connections. | Moveworks Owner Head of Employee Experience Software Engineers / Developers Business Systems Admins Business Analysts (for analytics) | | **Agent Studio Developer** | Create custom conversational AI use cases, and use API keys and connections to external platforms. | Head of Employee Experience Software Engineers / Developers Business Systems Admins | | **Agent Studio Analytics Viewer** | View analytics for your conversational AI use cases. | Head of Employee Experience Business Analysts (for analytics) | | **Agent Studio Log Viewer** | View run-time logs for plugins built using Agentic Automation (Plugins tab) in Agent Studio. | Software Engineers / Developers Business Systems Admins | | **Agent Studio Elevated Log Viewer** | See sensitive webhook-related logs for webhook-triggered plugins: `listener.webhook.trigger`, `listener.webhook.processor.update`, and `listener.webhook.plugin.trigger`. Must be used with Agent Studio Log Viewer. Assign only when necessary, as it grants visibility into potentially sensitive webhook payload data. | Software Engineers / Developers Business Systems Admins | ### Analytics | Role | What it can do | Typically assigned to | | ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | | **Bot Analytics Admin** | View Bot Performance Insights and Assistant Insights — including the assistant response to each user interaction — and grant or revoke access to assistant analytics. | Moveworks Owner Head of Employee Experience Business Analysts (for analytics) | | **Bot Analytics Viewer** | View Bot Performance Insights and Assistant Insights, including fine-grained interactions. | Moveworks Owner Head of Employee Experience Business Analysts (for analytics) | | **Interactions Viewer** | View assistant analytics, plus all user interactions with the assistant and their feedback. | — | ### Employee Communications | Role | What it can do | Typically assigned to | | ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------- | | **Employee Comms Admin** | Broadcast custom messages to all or a subset of users via the Moveworks bot, publish campaigns, and grant or revoke access to Employee Communications. | Moveworks Product Owner HR Business Partners System Administrators Finance Teams | | **Employee Comms Publisher** | Broadcast custom messages to all or a subset of users via the Moveworks bot, and publish campaigns. | Moveworks Product Owner HR Business Partners System Administrators Finance Teams | | **Employee Comms User** | View and edit campaigns in Employee Communications. | Moveworks Product Owner HR Business Partners System Administrators Finance Teams | ### Employee Experience Insights (EXI) | Role | What it can do | Typically assigned to | | --------------------- | --------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | | **EXI Admin** | Get Employee Experience Insights about the help desk and applications, and grant or revoke access to EXI. | Moveworks Owner Head of Service Desk Head of Employee Experience Business System Administrators | | **EXI User (Viewer)** | Get Employee Experience Insights about the help desk and applications. | Moveworks Owner Head of Service Desk Head of Employee Experience Business System Administrators | ### Knowledge Studio | Role | What it can do | Typically assigned to | | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | | **Knowledge Studio Admin** | Generate knowledge articles to fill gaps in your employee knowledge base, and grant or revoke access to Knowledge Studio. | Moveworks Product Owner IT System Administrators Knowledge Base Manager | | **Knowledge Studio User (Viewer)** | Generate knowledge articles to fill gaps in your employee knowledge base. | Moveworks Product Owner IT System Administrators Knowledge Base Manager | ## Add a Super Admin 1. Click on **Roles and Permissions**. ![](https://files.readme.io/9e98c45-image.png) 2. Click on **Add User**. ![](https://files.readme.io/f7fc710-image.png) 3. Search for your user by name or email. Check the **Super Admin** toggle, and click **Save**. ![](https://files.readme.io/958c8d0fcf963cfb9ba6c10b5d590287bc2fe8b1bc50abbe67ae71b723006c3c-CleanShot_2025-05-02_at_13.49.31.png) \ 4. Changes take effect in under 10 seconds, usually instantaneously. ## Remove a Super Admin Super Admin access cannot be revoked by other super administrators inside an organization. Please contact Moveworks Customer Support through the MyMoveworks portal to revoke a super admin. Feel free to use the following template: ``` Hello support, I would like to revoke superadmin access to user@example.com in my organization. I understand that only Moveworks and other superadmins in my organization can manage access to applications, and have read our RBAC documentation at /service-management/administration/my-moveworks-overview to understand the consequences of this action. Thank you Name ``` ## Add an Application Admin 1. Click on **Roles and Permissions**. ![](https://files.readme.io/6d809f1-image.png) 2. Click on **Add User**. ![](https://files.readme.io/12c420e-image.png) 3. Search for your user by name or email. Check the application toggle you would like to grant administrative access to, and click **Save**. ![](/_fern-img/cfc61c57c28106f1458a4d57ea13064d427fc19ebce6ba827c730aed58946d59.webp) Changes take effect in under 10 seconds, usually instantaneously. ## Remove an Application Admin 1. Click on **Roles and Permissions**. ![](https://files.readme.io/76f9ad4-image.png) 2. Search for a user by name or email, and click on the pencil icon to edit permissions for that user. ![](https://files.readme.io/58d5da3-image.png) 3. Uncheck the application toggle you would like to grant administrative access to, and click **Save**. ![](https://files.readme.io/5c38f4a9a26219b057a63a91760b39135ceec9bf2ae75eea8d4736865bbb9291-CleanShot_2025-05-02_at_13.51.34.png) Changes take effect in under 10 seconds, usually instantaneously. \ ## Add a User to an Application 1. Click on **Roles and Permissions**. ![](https://files.readme.io/2321e74-image.png) 2. Click on **Add User**. ![](https://files.readme.io/5dc85cc-image.png) 3. Search for your user by name or email. Check the application toggle you would like to grant user access to, and click **Save**. ![](https://files.readme.io/423bf5c9e391dba290ea12c4d73a1e98e2d117193b1861348491511258d06808-CleanShot_2025-05-02_at_13.52.05.png) Changes take effect in under 10 seconds, usually instantaneously. ## Remove a User from an Application 1. Click on **Roles and Permissions**. ![](https://files.readme.io/8a03c7e-image.png) 2. Search for a user by name or email, and click on the pencil icon to edit permissions for that user. ![](https://files.readme.io/88b2607-image.png) 3. Check the application toggle you would like to grant user access to, and click **Save**. ![](https://files.readme.io/46532622ba0f96f0ca87706ff042a38e64918213777688b4bcc5bd92036a5bae-CleanShot_2025-05-02_at_13.52.05.png) Changes take effect in under 10 seconds, usually instantaneously. ## Search for Permissions Assigned to User You can search for users by name or email to quickly validate permissions for that users. 1. Click on the 🔍 Magnifying Glass icon on the right-hand side to search for a user by name or email. ![](https://files.readme.io/3ac34a0-image.png) 2. As you type, the list of users filters down until you match the user you are looking for. ![](https://files.readme.io/9a06aaf-image.png) 3. Review the permissions assigned to this user. If the permissions do not match, you can click on the pencil icon and edit permissions for that user. ![](https://files.readme.io/aba669f-image.png) --- # Frequently Asked Questions (FAQ) 1. Can Moveworks view the roles and permissions in my environment or make changes in my environment on my behalf? 1. Yes – Moveworks uses an administrator account (similar to `moveworksadmin@.com`) to help you view your configurations, make roles and permissions changes, or take other actions on your behalf in your My Moveworks applications. This service account is automatically inserted into your user roster when you configure Moveworks. This account is not used for any other purposes. 2. Is audit data available when Moveworks makes changes in my environment, or when configuration details are viewed by Moveworks? 1. Moveworks stores internal logs of all role changes described in the previous section. You can reach out to Moveworks Customer Support team for access to this information. 2. Audit information for configuration changes in Moveworks setup or extensibility through Agent Studio is available to audit through SFTP. Please read our [SFTP data dictionary](/ai-assistant/moveworks-classic/analytics-1/moveworks-analytics-upgrade-faq) to learn more. 3. Do you plan to make audit data available through My Moveworks? 1. Yes, please upvote [this community idea](https://community.moveworks.com/idea-conversion-moderation-59/audit-logs-for-when-actions-are-taken-152?tid=152\&fid=59) to help the Moveworks team prioritize this feature 4. How long is this data retained by Moveworks 1. By default, audit logs of role changes are stored for a period of 2 weeks as part of our service logs. 2. Please read our [data retention deletion policy](/service-management/moveworks-setup/security-and-privacy-settings#data-retention-and-deletion-policy) to learn more 5. Can admins add more admins for their org? 1. Yes. Org Admins can assign “Org Admin” permissions to other users 6. Is there a maximum number of Org Admins? 1. There is no limit to the number of users who can be given Org admin permission. 7. What happens if an Org Admin is deactivated? 1. Other Org Admins will ensure continuity. If no Org Admin is active, please reach out the Moveworks Customer Support Team to provision a new Org Admin. ## Docs - [Role Based Access Control (RBAC) at Moveworks](https://docs.moveworks.com/service-management/administration/manage-roles-and-permissions-for-moveworks-applications/role-based-access-control-rbac-at-moveworks.md): - [How to Assign Roles using RBAC](https://docs.moveworks.com/service-management/administration/manage-roles-and-permissions-for-moveworks-applications/assigning-roles-using-rbac.md):