Skip to main content

Setting and Permissions

Overviewโ€‹

Setting and Permissions is the single admin console where you govern how your organization uses ChatLLM. From this one page you can:

  • Decide the default visibility of everything your members deploy.
  • Restrict features to specific user groups โ€” sharing, app deployment, Tasks, Skills, Desktop/CLI, Studio, MCP, and the Abacus AI Agent.
  • Control conversation sharing and privacy defaults.
  • Turn individual connectors off entirely, or allow them for agents only.
  • Enforce retention policies and daily/monthly dollar rate limits per organization, per group, and per user.
  • Stream audit logs to your own S3 bucket, Splunk instance, or an email distribution list.
  • Audit what already exists: every ChatLLM project, user Task, and first-party connector in the organization.

Changes made here apply to all members of the organization.

info

These controls are enterprise features and are managed by organization administrators.


Where to find itโ€‹

Sign in to ChatLLM, open the left navigation, and under ORGANIZATION select Setting and Permissions.

The page lives at:

https://<your-workspace>.abacus.ai/chatllm/admin/permissions/
Setting and Permissions in the ChatLLM left navigation

Who can use itโ€‹

RoleWhat they see
Organization adminThe full page โ€” all nine tabs.
Non-admin memberA lock panel: "You need organization admin privileges to manage these settings." The Audit Logs tab is hidden entirely.

Some controls are additionally gated:

  • Application Level Permissions requires a custom domain suffix configured for your organization.

Page layoutโ€‹

The page is organized into nine tabs:

#TabPurpose
1Application Level PermissionsDefault access level for deployed apps
2Access & RestrictionsGroup-based feature restrictions
3Sharing & PrivacyConversation sharing and privacy defaults
4Features & IntegrationsConnectors, email domains, global skills and context
5Data & UsageRetention policy and rate limits
6Audit LogsHourly audit/activity export
7View ChatLLM ProjectsRead-only inventory of projects
8View User TasksRead-only inventory of Tasks, with pause/delete
9View First Party ConnectorsRead-only inventory of connectors and MCP servers

1. Application Level Permissionsโ€‹

Sets the default deployment access level for apps deployed in your organization.

Application Level Permissions tab with the Organization Level Permission card
OptionEffect
Private to OrgRestricted to organization users only.
Owner OnlyVisible only to the creator/owner.
PublicOpen to the internet.

2. Access & Restrictionsโ€‹

This is the primary tab for limiting who can do what. Each card is a searchable multi-select of user groups, and there are two distinct polarities:

  • Restrict-type cards โ€” the groups you add are denied the capability. Everyone not in those groups keeps it.
  • Allow-type cards โ€” when no groups are selected, everyone has access. As soon as you add a group, access is limited to that group (plus admins).
tip

Set up your user groups first under Users and Groups, then come back here to attach restrictions to them. External groups (for example, from SSO/SCIM) are automatically migrated when you select them.

Sharing, apps, and Tasksโ€‹

Access and Restrictions โ€” project sharing, AppLLM sharing and deployment, custom domain deployment, Tasks access
CardTypeWhat it does
Restrict ChatLLM Project SharingRestrictSelected groups have restricted access to ChatLLM project sharing features.
Restrict AppLLM SharingRestrictUsers in these groups can only create private apps visible to themselves, and cannot change the access level of apps.
Restrict AppLLM DeploymentRestrictUsers in these groups can view AppLLM apps but cannot deploy. They can still view files and edit code.
Custom Domain DeploymentToggleDisable deployment on custom domain. When enabled, non-admin users will not see the custom domain/subdomain deploy options. Admins can always deploy.
Restrict Tasks AccessRestrictUsers in these groups will not be able to see or access Tasks.

Skills, Desktop, Studio, and MCPโ€‹

Access and Restrictions โ€” skill creation, Abacus AI Desktop, Abacus AI Studio, MCP connector access
CardTypeWhat it does
Restrict Skill CreationRestrictUsers in these groups will not be able to create or upload skills.
Abacus AI Desktop AccessAllow + toggleLimits who can use Abacus AI Desktop. The toggle Disable Abacus AI Desktop, CLI, and VS Code extension switches all three off for the whole organization and hides the desktop download button. Admin users always have access.
Abacus AI Studio AccessAllow + toggleLimits who can use Image, Video, and Speech generation. The toggle Disable Abacus AI Studio removes it for everyone.
MCP Connector AccessAllow + toggleLimits who can configure MCP servers. Only permitted users see the Configure MCP option. The toggle Disable MCP Connector removes it for everyone.

Abacus AI Agent accessโ€‹

Access and Restrictions โ€” Abacus AI Agent access

Abacus AI Agent Access controls which user groups can access the Abacus AI Agent, and the Disable Abacus AI Agent toggle turns it off organization-wide.

warning

Restricting or disabling the Abacus AI Agent significantly impacts user experience โ€” it is the primary agentic surface in ChatLLM. Confirm with your teams before switching it off.


3. Sharing & Privacyโ€‹

Three organization-wide toggles that govern conversation visibility.

Sharing and Privacy tab with the three conversation privacy toggles

Disable Public Conversation Sharingโ€‹

Prevents users from making chat conversations publicly accessible via share links.

warning

When enabled, existing public share links will no longer be accessible. Any link you have already circulated outside the organization stops working immediately.

Make Conversations Private by Defaultโ€‹

All new conversations become private and visible only to the creator. Users must then explicitly share a conversation with specific users or groups. Admins can always access all conversations.

Restrict ChatLLM Project Global Sharingโ€‹

Removes the share with the entire organization option. Users can still share conversations with specific users or groups.


4. Features & Integrationsโ€‹

Connectors and showcase panelsโ€‹

Features and Integrations โ€” GitHub connector, connector email domain enforcement, showcase panels, connectors policy table

Disable GitHub Connector hides the connect your GitHub option for all users. It does not disconnect existing GitHub connections.

Enforce Connector Email Domain requires user connector accounts to use an email from your organization's allowed domains. The card lists every connector whose connected-account email is validated: Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, YouTube, Outlook, OneDrive, SharePoint, Microsoft Teams, Slack, Box, Dropbox, Jira, Confluence, Salesforce, HubSpot, QuickBooks, DocuSign, Zoom, Smartsheet, Figma, and Monday.com.

note

GitHub, Tableau, and X (Twitter) are not enforced, because a verified account email is not reliably available from those providers.

Hide Abacus AI Agent Showcase Panels hides the Abacus AI Agent video showcase panels from the home page.

Connectors Policyโ€‹

The Connectors Policy table gives per-connector control over how each integration can be used.

ColumnMeaning
ConnectorThe integration name.
User-levelHides the connector from personal connections and from the agent's tools.
Fully disableBlocks the connector everywhere.
StatusEnabled (green) ยท User-level off (amber) ยท Disabled (red).

Turning one toggle on turns the other off. Existing connections are not affected. Click Save changes to apply.

Allowed Email Domainsโ€‹

Features and Integrations โ€” allowed email domains, global skills, global context

Restricts the Send Email Tool to only send emails to specific domains. Type a domain (for example abacus.ai), click Add, and it appears as a chip you can remove. Leave the list empty to allow all domains.

note

This applies only to the native send-email tool. It does not apply to first-party connector tools such as Gmail and Outlook.

Global Skillsโ€‹

Designate skills as global for your organization. Global skills are enabled for all users by default and cannot be removed or disabled by non-admin users. Only admins can add or remove them from this page.

warning

Each global skill increases token usage for every conversation. Skill instructions may also conflict with existing system prompts or other skills, potentially causing unexpected behavior.

Global Contextโ€‹

Organization-wide context that is automatically added to every conversation for all users, in both chat and agents (SuperAgent / DeepAgent). Limited to 3,000 characters; the counter next to the field shows your usage.

Example: "Our company is Acme Corp. Always use British English. Never mention competitor products by name."

warning

Global context is injected into every conversation and increases token usage on every message. It may conflict with existing system prompts, skills, or a user's own custom instructions. Keep it short and focused.

This card is visible to organization admins only.


5. Data & Usageโ€‹

Organization Retention Policyโ€‹

Data and Usage tab โ€” organization retention policy and rate limits

Set the number of hours to retain deployment conversations. Conversations older than the specified value are automatically deleted. Leave the field empty and save to remove the policy.

note

Deployment-specific retention overrides org-level retention.

Rate Limitsโ€‹

Set dollar limits for your organization. Users exceeding their limit are blocked until the quota resets.

Limit Period โ€” choose whether the dollar limits apply Daily or Monthly, then click Save.

  • Daily limits reset at 2 pm UTC.
  • Monthly limits reset at the start of the next month, 12 am UTC.

Rate limits are split across three sub-tabs:

Global Limitโ€‹

A single dollar limit per period, per user, applied to everyone in the organization. The card shows the currently applied value, for example Current limit: $30.00 per day per user.

Group Limitsโ€‹

Rate Limits โ€” per-group dollar limits

Search for a user group and set a dollar limit for it. Each group row shows its current limit and links through to the group's page under Users and Groups.

note

Users get the maximum of their group limit and the global limit. If a user is in multiple groups, the highest limit applies.

Usersโ€‹

Rate Limits โ€” per-user temporary overrides and usage

Temporarily raise a specific user's limit. Search by name or email; each row shows usage against the effective limit ($X used / $Y), a Throttled badge when the user is currently blocked, and any active override as Temp limit ยท Nd left with the underlying base limit.

Click Set temp limit (or Edit temp limit) to open the dialog. An override:

  • Only ever raises a user's limit above their group/global limit.
  • Expires automatically โ€” the duration is specified in hours, up to 720 hours (30 days).
  • Takes effect within a few minutes.

The button is disabled if the user has no base limit yet: "Set a group or global rate limit before adding a temporary limit for this user."

note

Rate limits do not impact development or API usage โ€” the usage figures shown represent non-API usage only.


6. Audit Logsโ€‹

Deliver your organization's audit and conversation activity to your own systems once an hour. Each run covers the previous clock hour.

info

If you see "Audit log export is not available for this organization", contact your Abacus.AI representative to have audit log export enabled.

This section describes the configuration UI. For the delivered record format, field-level schema, and history re-delivery, see Audit Log Export.

What gets exportedโ€‹

Every delivery is a single JSON file containing the events recorded in that hour:

Event groupContents
Audit eventsMember and permission changes, API key activity, and other recorded admin actions.
Conversation activityEach assistant turn with the user, app, model, and request id.
Conversation lifecycleConversations created and deleted, with the acting user.
Project activityChatLLM projects created, with the acting user.
Request metadataExternal service actions and the originating IP address.

Destinationโ€‹

Pick where the hourly export is delivered โ€” only the selected destination receives it.

Audit Logs โ€” destination selector open showing all four export targets, with the Splunk fields below

Abacus.AI managed storageโ€‹

The default. No further configuration required.

Cloud storage bucketโ€‹

Audit Logs โ€” cloud storage bucket destination

Provide a Bucket URI for Amazon S3, Google Cloud Storage, or Azure โ€” s3://, gs://, or azure:// (for example s3://my-bucket/audit-logs).

note

The bucket must already grant Abacus.AI write access โ€” add it under User Connectors first. Azure additionally needs a stored connection string.

Splunkโ€‹

Shown in the screenshot above. Fill in:

FieldNotes
HEC endpointYour Splunk HTTP Event Collector address, including the port.
IndexLeave blank to use the token's default.
Source typeDefaults to abacus:auditlog.
HEC tokenOnce stored it is never displayed again โ€” leave blank to keep the current token.

Show advanced options exposes Skip TLS verification and Send uncompressed.

You must allow inbound traffic from the Abacus.AI egress IP addresses listed on the card so the exporter can reach your collector.

warning

Use the collector address exactly as Splunk gives it, including the port โ€” a stack hostname on the wrong port will redirect and silently drop events.

Emailโ€‹

Audit Logs โ€” email destination with recipient chips

Add one or more recipient addresses as chips. At least one recipient is required.

note

Email is best suited to low-volume organizations โ€” a busy hour produces a large attachment.

Changes on this tab are staged: a sticky bar at the bottom shows You have unsaved changes until you click Save changes.


7. View ChatLLM Projectsโ€‹

A read-only inventory of all ChatLLM projects in your organization, with creator and sharing information.

View ChatLLM Projects โ€” organization-wide project inventory

Columns: Project Name, Creator, Access Level, Shared With, Created, and Actions. Search by project name or email, and page through the results (10/25/50/100 per page).

The Access Level column uses these labels:

LabelMeaning
PrivateOnly the creator.
Private to OrgEveryone in the organization.
Private to Org (No Convos)Organization-wide, but conversations are not shared.
Private to Org (View Only)Organization-wide, read-only.
User GroupsLimited to specific groups.
Groups (No Convos)Specific groups, without conversations.

Clicking Shared With opens Shared Access Details, listing the individual Users and Groups the project is shared with and their permission โ€” Can View, Can Edit, or View (No Convos).

Only organization admins can see this information.


8. View User Tasksโ€‹

Every Task created by users in your organization.

View User Tasks โ€” organization-wide task inventory with pause and delete actions

Columns: Task Name, Created At, User Email, Frequency, Status, and Actions. Status is ACTIVE or PAUSED.

This is the one View tab that is not read-only โ€” admins can pause or delete any user's task, which is useful for stopping a runaway scheduled task or cleaning up after a departed member. Search by task name or email to find a specific task.


9. View First Party Connectorsโ€‹

All connectors and MCP servers created by users in your organization.

View First Party Connectors โ€” organization-wide connector inventory

Columns: Connector Type, Name, Created By, Status, and Created. Search by connector type, name, or email.

Use this tab to audit which third-party services members have actually connected before deciding what to lock down in the Connectors Policy.


Quick reference: every way to limit accessโ€‹

GoalWhereControl
Make deployed apps private by defaultApplication Level PermissionsPrivate to Org / Owner Only
Stop a group from sharing ChatLLM projectsAccess & RestrictionsRestrict ChatLLM Project Sharing
Force a group to build private-only appsAccess & RestrictionsRestrict AppLLM Sharing
Let a group code but not deployAccess & RestrictionsRestrict AppLLM Deployment
Block custom-domain deploys for non-adminsAccess & RestrictionsCustom Domain Deployment toggle
Hide Tasks from a groupAccess & RestrictionsRestrict Tasks Access
Prevent skill creation/uploadAccess & RestrictionsRestrict Skill Creation
Limit or disable Desktop / CLI / VS CodeAccess & RestrictionsAbacus AI Desktop Access
Limit or disable image/video/speech generationAccess & RestrictionsAbacus AI Studio Access
Limit or disable MCP serversAccess & RestrictionsMCP Connector Access
Limit or disable the Abacus AI AgentAccess & RestrictionsAbacus AI Agent Access
Kill public share linksSharing & PrivacyDisable Public Conversation Sharing
Make every new conversation privateSharing & PrivacyMake Conversations Private by Default
Remove "share with whole org"Sharing & PrivacyRestrict ChatLLM Project Global Sharing
Hide the GitHub connectorFeatures & IntegrationsDisable GitHub Connector
Require corporate emails on connectorsFeatures & IntegrationsEnforce Connector Email Domain
Disable a specific connector everywhereFeatures & IntegrationsConnectors Policy โ†’ Fully disable
Allow a connector for agents but not personal useFeatures & IntegrationsConnectors Policy โ†’ User-level
Restrict outbound email recipientsFeatures & IntegrationsAllowed Email Domains
Push mandatory instructions to everyoneFeatures & IntegrationsGlobal Skills / Global Context
Auto-delete old conversationsData & UsageOrganization Retention Policy
Cap spend for everyoneData & UsageRate Limits โ†’ Global Limit
Cap spend per teamData & UsageRate Limits โ†’ Group Limits
Temporarily raise one user's capData & UsageRate Limits โ†’ Users
Stream activity to SIEMAudit LogsDestination โ†’ Splunk / bucket / email
Stop a runaway scheduled taskView User TasksPause / Delete