Skip to main content

Types of roles in Sana

J
Written by Johan Åkerman

Introduction

Access to Sana is defined by your assigned role, which determines the features you can use and the settings you can manage. There are two roles in Sana: Member and Admin.

  • Members use Sana to ask questions, take actions, upload files, and connect apps.

  • Admins can do everything a Member can, and additionally configure workspace-level settings.

Roles are assigned in Workday and mirrored into Sana automatically. If you need to change a user's role, contact your Workday Admin or HR/IT counterpart — this cannot be done inside Sana.


Roles

Your role determines your level of access to workspace configuration:

Role

Description

Member

The standard user role. Members can ask questions through chat, search for information, upload files, interact with connectors to access their organization's knowledge, and take actions (e.g., sending an email). Members cannot change any workspace settings.

Admin

Admins can perform every action that a Member can, and in addition configure workspace-level settings. This includes changing the workspace name, toggling connector availability, managing email domain restrictions, and setting web search defaults.


Capabilities overview

Feature / Capability

Member

Admin

Add context with files, web, and apps

Upload documents (PDF, spreadsheet, slide deck, image) for analysis

Toggle Web Search on/off per conversation

Connect personal accounts (Gmail, Drive, Outlook, Salesforce, Zoom)

Manage your account

View and continue past conversations from chat history

View your profile

Manage connected apps

Export personal data (chats and files)

Configure the workspace

Change workspace name

Set web search default for new conversations

Toggle customer support chat (Intercom)

Enable / disable connectors for all users

Restrict email domains

View members, licenses, and roles

Note: Only the Workday connector is available to Sana Core users. Other connectors are only available to Sana Enterprise users. Please check with your Workday Admin if you're unsure about your license.


User management

Sana does not have a separate user management system. All user lifecycle, license assignment, and role assignment are controlled in Workday and mirrored into Sana:

  • Provisioning: Users are automatically created in Sana when they are added to the appropriate provisioning groups in Workday and synchronized via SCIM.

  • Role mapping: The Workday configuration determines whether they are assigned the Admin or Member role.

  • De-provisioning: Removing or disabling a user in Workday automatically revokes their access to Sana. No additional action is required in the Sana workspace.

If you need to change a user's license or role, contact your Workday Admin.


FAQ

Q: Can I change a user's role directly in Sana?

A: No. Both are synced from Workday. To make changes, update the user's assignment in Workday. The change will appear in Sana automatically after the next SCIM sync.

Q: Can a Member be promoted to Admin?

A: Yes, but not from inside Sana. Admin access is granted by assigning the user to the appropriate Workday group that maps to the Admin role. Contact your Workday Admin.

Q: Do Admins have access to all data in Sana?

A: No. Admins can configure workspace-level settings and connectors, but they cannot see other users' private chats or files. Chat and file access remain private to the signed-in user.

Did this answer your question?