Skip to main content

Users and Access Controls

Understand the roles in a thunk, add or remove people, and transfer ownership

Every thunk has its own list of users. Each user has one role in that thunk, and the role decides what they can see and do. This article covers access to a single thunk. For organization membership and environments, see Orgs, Roles, and Environments: Enterprise Administration Guide.

Roles in a thunk

There are four roles within a thunk:

  1. Owner: the user who owns the thunk. Every thunk has exactly one Owner. Any AI logic in the thunk runs with the identity of the Owner and uses the application connections in the Owner's account. The Owner is also an Admin and can delete the thunk.

  2. Admin: a user who designs the logic of a thunk and can monitor its execution. Admins can change the definition of the thunk, see and edit all data, assign work, and add or remove other users.

  3. Human Agent: a user who may be assigned a work step as part of the thunk workflow. The human agent along with their AI agent are responsible for performing that step, and can approve or change its results.

  4. End User: a user who can use the thunk only through its chat interface. End Users cannot see the work items, the plan, the settings, or other users' data. See Set up the hosted Chat UI for your thunk.

Typically, the Owner, Admins, and Human Agents are all members of the team or organization providing the workflow application or service.

Owners and Admins can modify the logic of the thunk (the workflow plan, the AI instructions, etc.).
Human Agents can only work on steps assigned to them. To see the work items where a step is waiting on you, use the Waiting on me view.

Admins and Human Agents should be people you trust. Before you add one, read Authorization and authentication.

Add people to a thunk

Only the Owner and Admins can add or remove users. There are two ways to add someone.

From Share (quickest for several people at once):

  1. Open the thunk and click the Share icon in the header.

  2. Enter one or more email addresses.

  3. Choose a role: Admin, Human Agent, or End User.

  4. Click Invite.

From Users and Roles:

  1. Open the thunk and choose Admin → Users and Roles in the left navigation.

  2. Find the section for the role you want: Admins, Human Agents, or End Users.

  3. Enter the person's email address and click the add button in that section (for example, Add Admin).

You can add someone who has not signed in to Thunk.AI yet. They get access to the thunk when they sign in with that email address. Let them know the thunk is ready and send them its link. Some private instances only allow adding people who already have an account.

Change a role or remove someone

A person can hold only one role in a thunk. To change someone's role, remove them and add them again with the new role.

To remove someone, open Admin → Users and Roles and click Remove next to their name.

Transfer ownership

Only the current Owner can hand a thunk to someone else, and the new Owner must already be an Admin of the thunk and able to use the thunk's environment. Because AI agents run as the Owner, the new Owner must agree first:

  1. The Owner opens Admin → Users and Roles, clicks Change next to their name in the Owner section, chooses the new Owner, and clicks Submit. The request shows as Pending approval.

  2. The new Owner opens Users and Roles in the same thunk, clicks Accept, and confirms with Approve ownership transfer.

  3. The Owner now sees Approval granted: try the change again. The Owner clicks Change again, chooses the same person, and clicks Submit to complete the transfer.

After the transfer, the AI agents in the thunk run with the new Owner's identity and use the application connections in the new Owner's account. Make sure the new Owner has the connections the thunk needs.

Did this answer your question?