Skip to main content
Beta Enterprise Agent permissions are behind the agent-identity feature flag. On Lightdash Cloud, ask Lightdash support to turn it on for your organization. On a self-hosted instance, enable the flag. What Beta means.
By default, an agent can do what the person who asked can do. Agent permissions let an organization admin limit that: which actions agents may take for each role, in which projects, and for which people. Limits only reduce what agents can do. They never give a person more access than their roles allow. Agent identity decides who agents run as in the warehouse. Agent permissions decide what agents may do in Lightdash.

Turn on limits

Agent permissions are in the Permissions section of Organization settings → Agent identity, after the identity rules.
1

Turn on the switch

Turn on Limit what agents can do. While it is off, agents follow each person’s permissions, as before.
2

Review the starting limits

The page shows the starting limits before anything is saved: for every role, Read, Query, Export and Raw SQL are on, and every change is off.
3

Save

Change the limits if you need to, then select Save.
The Permissions section with Limit what agents can do turned on and the starting limits: Read, Query, Export and Raw SQL checked for every role, all Changes unchecked, Allowed projects set to All projects and Who can use agents set to Everyone the roles allow
To turn the limits off, turn off the switch and confirm Turn off limits. Agents then follow each person’s permissions again, and the project and people limits no longer apply. If another admin saves first, the page says so and offers to reload. Lightdash refuses a save made from an out-of-date page.

What agents can do for each role

The matrix has one row for each role and one column for each capability. An agent can do something only when the person’s role allows it and the matrix allows it for that role.

Raw SQL needs the warehouse confirmation

Raw SQL lets an agent run SQL outside the data models, so Lightdash also needs a project admin to confirm that the warehouse limits what the agent’s identity can read. Each project has a Raw SQL for agents card on Project settings → Agent identity, for every warehouse:
1

Check the warehouse

Make sure the warehouse identity that agents run as can read only what agents may see. See Agent identity.
2

Confirm

On the Raw SQL for agents card, tick The warehouse limits what the agent’s identity can read, then confirm.
The card shows Not confirmed, Confirmed with who confirmed and when, or Expired when the connection changed after the confirmation. Select Remove confirmation to withdraw it. Raw SQL also needs to be allowed by the agent’s role and the organization limits.
The Raw SQL for agents card: Confirmed by David Attenborough on 10/10/2026, the note Raw SQL also needs to be allowed by the agent's role and the organization limits, and a Remove confirmation button

Allowed projects

Under Allowed projects, choose All projects, or Only these projects and select the projects. Agents run only in the allowed projects.

Who can use agents

Under Who can use agents, choose:
  • Everyone the roles allow. Every person’s agent can run, within the role limits.
  • Only these people. Only the agents of the selected people can run, on top of the role limits. A person who leaves the organization drops out of the list.
Allowed projects set to Only these projects with Jaffle shop selected, and Who can use agents set to Only these people with one person selected
When you save Only these people with no one selected, a warning opens: “No one’s agents can run”. If you confirm, no agent runs for anyone. Cancel keeps the previous list. To allow agents again, add people or choose Everyone the roles allow.
The No one's agents can run confirmation: No people are selected. If you save this list, no agent will run for anyone. Add people or choose Everyone the roles allow to allow agents again, with Cancel and Confirm buttons

Custom roles

Enterprise Custom roles have an Agent permissions group in the AI Features section of the role editor, with the 11 capabilities above. A new custom role starts with Read and discover, Query data, Export results and Raw SQL on.
The custom role editor with the AI Features section open and the Agent permissions group, with Read and discover and Query data checked under Read and query

Personal access tokens

Personal access tokens are not limited. An agent that uses a person’s personal access token, for example through MCP, has that person’s access.