Skip to content

Roles overview

Permissions are how Rival Enterprise provides your organization with the speed of automated AI without sacrificing control, auditability, or compliance. Every user in Rival holds a specific role that governs what actions they can perform, what data and tools they can see, which models they can query, and which system operations require administrative approval before completion.

Rival structures platform access across three primary roles designed for distinct operational goals:

Standard Rival User

Goal: get work done independently. The self-serve, non-enterprise baseline. Functions like an independent user with full personal freedom over tools, models, and billing.

Enterprise Admin

Goal: manage and govern AI across the organization. IT, security, and operations leadership. Defines global guardrails, manages user lifecycles, configures connectors, and maintains complete system visibility.

Enterprise Team Member

Goal: execute daily work within company guardrails. Enterprise employees. Actively builds and runs automations using approved tools, vetted connectors, and required approval checkpoints.

For the granular, action-by-action breakdown, see the Capability matrix.

The platform’s permission structure rests on a clear division of authority:

  • Standard Rival Users can execute any operation for themselves in an unmanaged workspace, taking on full responsibility for their own data, credentials, and billing.
  • Enterprise Admins establish global security rules, approve marketplace asset catalogs, manage team budgets, and enforce model guardrails.
  • Enterprise Team Members operate freely and efficiently inside those pre-established administrative boundaries without needing to hand-code security checks or manage credentials.

Designed for standalone builders and individuals operating outside an enterprise workspace boundary:

  • Asset creation — full authority to build, edit, and publish custom functions, agents, and workflows for personal use.
  • Model selection — unrestricted access to any supported foundation model available on the platform.
  • Resource management — direct management of individual run balances, personal API keys, and private system connections.

Designed for IT, security, and department leadership requiring full administrative command over organizational AI adoption:

  • Governance and policies — configure global model guardrails, restrict PII transmission, and define approved marketplace catalogs. See Guardrails and allowed models.
  • Access and provisioning — manage SSO and SCIM integrations, invite users, organize teams, assign roles, and revoke access instantly. See User lifecycle.
  • Financial oversight — set departmental cost controls, track usage telemetry across teams, and allocate run balances centrally. See the Cost Optimization Center.
  • Approval gates — review and approve pending marketplace submissions, connector access requests, and high-consequence workflow actions. See Approval workflows.

Designed for employees executing business tasks and building team-level automations inside governed environments:

  • Approved capabilities — access and execute all admin-vetted tools, agents, and workflows published to the internal marketplace catalog.
  • Guided creation — construct new custom tools and agents using visual builders or RivalBot, which automatically submit to the admin queue upon publication.
  • Scoped integrations — interact with central enterprise connectors explicitly granted to their team or role. See Connector governance and security.

A quick example: governed automation lifecycle

Section titled “A quick example: governed automation lifecycle”

Consider how roles interact when deploying a new customer support automation:

  1. Rule definition — an Enterprise Admin configures global guardrails blocking the transmission of customer PII and approves specific support connectors.
  2. Safe execution — an Enterprise Team Member builds an agent to draft ticket responses, operating smoothly within the approved connectors and rules.
  3. Escalation gate — when the team member’s agent attempts a high-impact operation, such as issuing a customer refund, the system pauses execution automatically and routes an approval request to the Enterprise Admin.
Operational areaStandard Rival UserEnterprise AdminEnterprise Team Member
User and team managementFull controlView team members
Tool and agent creationUnrestrictedUnrestrictedGuided / governed
Publishing to org catalogDirect (personal)Direct (org-wide)Requires admin approval
Connector accessPersonal accountsCentral setup and assignmentAssigned / approved only
System audit logsPersonal onlyGlobal enterprise visibilityTeam-scoped activity