Articles in this section

Create and manage end user roles

End user roles simplify access management by letting you assign a predefined set of MCP server permissions to end users and groups.

Instead of configuring access to each MCP server individually, create a role that defines the servers and capabilities users should have, then assign that role wherever it's needed. Updating the role automatically updates access for everyone assigned to it.

For example, you could create a NetSuite team role that grants access to the NS production and NS sandbox MCP servers with the appropriate capability sets. Assign the role to a group, and every member receives the configured access.

Note: Roles are optional. You can continue assigning MCP server access directly to end users and groups.

Before you begin

  • You must have the Administrator role.
  • At least one MCP server must exist.
  • If you plan to assign capability sets, create them on the target MCP servers first.

Create a role

  1. Go to Account, and then select Users.
  2. Go to End user > Roles.
  3. Select Create role.
  4. Enter a Role name and an optional Enter a description.
  5. In the MCP section, select Assign MCPs.
  6. Select one or more MCP servers and select Save & close.
  7. For each server, select the required from the Capability sets, Tools, Prompts, Resources, APIs,  or individual capabilities the role should grant.
  8. To grant access to every MCP server in the account, select All MCP servers.
  9. Select Save.

The role is now available for assignment.

Assign a role

You can assign a role to either a group or an individual end user.

Assign a role to a group

  1. Go to End user > Groups.
  2. Open the group you want to update.
  3. In the Roles section, select one or more roles.
  4. Select Save.

Every member of the group inherits the access defined by the assigned roles.

Assign a role to an end user

  1. Go to End user > End Users.
  2. Open the end user.
  3. In the Roles section, select one or more roles.
  4. Select Save.

The end user immediately receives the access defined by the assigned roles.

View effective access

To understand why an end user has access to an MCP server or capability:

  1. Go to End user > End users.
  2. Select the end user.
  3. Review the Effective access section.

Each entry identifies how access was granted:

  • Through a role
  • Through a group
  • Through a direct assignment

If access is granted through multiple sources, all applicable sources are displayed.

Edit a role

  1. Go to End user > Roles.
  2. Open the role.
  3. Update its name, description, MCP servers, or capability assignments.
  4. Select Save.

Changes apply automatically to all groups and end users assigned to the role.

Delete a role

  1. Go to End user > Roles.
  2. Open the role.
  3. Select Delete.
  4. Confirm the deletion.

Deleting a role removes only the access granted by that role. Access granted through other roles, groups, or direct assignments remains unchanged.

How role based access works

Roles are account-level resources that can include one or more MCP servers. For each server, you specify which capability sets or individual capabilities the role grants.

Roles don't replace direct access assignments. You can continue granting access directly to groups or end users, or use a combination of both approaches.

An end user's effective permissions are the combined result of:

  • Roles assigned directly to the user
  • Roles inherited through groups
  • Direct group-to-server assignments
  • Direct end-user-to-server assignments

When a role is updated, the changes automatically apply everywhere the role is assigned.