Skip to main content
After users have received the permission to access the platform, additional permissions are required to view Agents and their corresponding knowledge. Our role-based permission concept is designed so that complex permission structures can be implemented at agent level.
To manage the platform and access every Agent in both the admin panel and the Agent Hub, you will need the ‘Global Admin’ permission. Please take a look at the permissions scheme below. Please also make sure to assign this role to Genow.

How to Manage Permissions

When setting up Genow, you can choose from two different approaches for managing permissions. We recommend deciding on this at the start of the setup process. If you wish to change your chosen approach, please contact Genow. Both options generally work in parallel, but we recommend choosing one option and sticking to it.
Share entities directly to individual users by entering their email address - or add multiple users at once via a CSV file. This gives you the most flexibility and the lowest overhead, without needing to maintain group structures in your IAM for every scenario. Please let us know if you would like this option to be made available to use case administrators as well.
By default, Agent Admins can create new Knowledge Sources within their Agent. If needed, this permission can be restricted so that only Global Admins can create sources. Contact Genow to enable this restriction for your platform.
If you are using Google SAML, you can also share knowledge entities with Workspace groups using their email.
You can share knowledge entities with Entra ID groups by entering the group’s Object ID in the sharing dialog. Before you can use this, a one-time setup in your Entra ID app registration is required - see the expandable guide below. If you want to use group claims/emails, your Entra ID or Workspace administrator will need to create a group for each user group in Entra ID or Workspace, assigning individual access rights. They will then need to use the group claim in the admin panel to share knowledge entities.
To ensure users can log in to the platform, at least one authentication group containing all end users must still exist in your IAM system.

Option 2: IAM Permission Management with Role Permissions

Permissions are managed directly in your IAM system using App Roles in Entra ID or Google Workspace groups assigned via the Admin Panel. Each permission level is defined as an individual App Role or group assignment. This approach offers the most granular control and is fully supported alongside the newer option. If you need custom roles that hold a subset of permissions of an Agent (e.g. the permission to only access a specific asset or source), you will need to reach out to Genow.

How to Share Knowledge Entities Or Create And Permissions

Creating user permissions is done in two steps:
1

Identify groups and create roles

Identify relevant admin and user groups for your use cases.
2

Share knowledge entitiy or create permissions yourselfes

Share knowledge entities via the share button (option 1 ) or create your permissions in either Entra ID or directly assign permissions to Google Workspace groups via the user configuration in the admin panel (option 2).
3

Share knowledge entity or create permissions yourself

Share knowledge entities via the share button (option 1 ) or create your permissions in either Entra ID or directly assign permissions to Google Workspace groups via the user configuration in the admin panel (option 2).

(1) Identify and create Groups

If you are setting up Genow the first time, please identify a group of platform admins first, which will be able to manage the platform itself as well as create and manage every agent on the platform. This group of people will receive the global.Admin role either via Entra ID or the admin panel. Follow the guide for option 2 to do this one time.
When it comes to creating and introducing a new agent, the agent admin, which will manage the agent corresponding to his domain or team, should think about whether there are different user groups with different access rights to specific agent data.

(2) Create and Assign Permissions

In addition to managing permissions via your IAM system (Entra ID or Google), Agents, Knowledge Assets, and Knowledge Sources can now be shared directly from within the admin panel - no external configuration required.
In-app sharing must be activated for your environment. Contact your Genow administrator if the Share button is not visible in your admin panel.

How It Works

A Share button is available on every Agent, Knowledge Asset, and Knowledge Source - both in the overview table and in the detail view. Clicking it opens a sharing dialog where you can grant access to:
  • Option 1: Groups - by group email (Google SAML with Workspace) or by group Object ID from Entra ID.
    Please note, that you have to perform a one time IT setup for those groups. Expand the “One-Time Setup: Configure Entra ID for Group Sharing” section below to learn more.
    (Entra ID - requires one-time IT setup, see expandable guide below).
  • Option 2: Individual users - by email address - or multiple entries at once - via CSV bulk upload
If you want to share entities to groups, you first have to create them. You can find a short guide on how to do this below.

Sharing Levels

The scope of access depends on which entity you share:

Who Can Share What

Managing Existing Shares

The sharing dialog shows which users and groups have direct access to each entity. You can revoke any share from this screen. Only direct shares are listed - indirect access (e.g. from a parent Agent share) is not shown at the source level.
Export the groups emails of your Google Groups and assign the needed roles via the User Configuration in the admin panel.