Who can do what in Sasha
Three roles
Every person in your Sasha has one of three roles: admin, staff or member. The role decides what the person can do.
Admin
- Can do everything that a staff account can do.
- Adds and removes people, and changes the role of a person.
- Chooses which shared projects each member can reach, and at which level of access.
- Manages the settings of your Sasha.
Staff
- Chats with Sasha in the Sasha web interface.
- Sees every project, members' homes included: in the project lists, in the file lists and from Claude.
- Sees and works in every member's home. In the Sasha web interface and from Claude, opens, adds and changes the documents in a home. In the Sasha web interface, also chats in it. Cannot delete or move the home itself; an admin removes a home by removing the member. See How Sasha organises your knowledge into projects and documents.
- Runs skills and builds skills. A skill is a packaged way of doing a task that Sasha can run.
- Works with meetings and meeting transcripts.
- Connects Claude to Sasha.
- Cannot manage people, roles or the settings of your Sasha.
Member
- Cannot sign in to the Sasha web interface. A member uses Sasha from Claude.
- Sees their own home and the shared projects that an admin gave them access to. For what a home is, see How Sasha organises your knowledge into projects and documents.
- Connects Claude to Sasha.
- From Claude, if your Sasha is set up to allow it, writes documents in their home and in the shared projects they were given write access to. A member cannot delete documents in a shared project.
- Cannot run skills or work with meetings. A member with access to a project can read a saved meeting transcript in it from Claude, like any other document.
What an admin can change for a person
An admin can change the role of a person. The new role then decides what that person can do.
For a member, an admin also chooses the access to each shared project: no access, read, or read and write. A member cannot delete documents in a shared project, at any level of access.
When a member gets a different role, Sasha removes their access to shared projects. Their home is kept. As staff or admin, they see it like every other member's home.
Who can see a member's home
Admin and staff accounts see and work in every member's home, in the Sasha web interface and from Claude. A member's home is private only from other members. An organisation that needs homes that no admin can see needs its own Sasha.
The rights to manage people, roles and settings belong to admins only. An admin cannot give them to a staff or member account.
What a Claude connection can reach
Every role can connect Claude to Sasha (Connect Claude to your Sasha). When you connect, Sasha asks you to allow what the connection will be able to do.
A connection is never more than you have in Sasha:
- Claude reaches only the projects that you can reach.
- If your access in Sasha gets smaller, the connection gets smaller too.
- If you get a new role, the connection keeps the permissions it had. Connect Claude again to use the new role.
- A shared project that an admin gives you is reachable from Claude at once.
A member's connection can do less than an admin or staff connection, because the member role can do less. For example, a member's connection cannot run skills.
For what Sasha holds, see What Sasha is and what Sasha holds.
For the exact permissions a Claude connection can hold, see the MCP reference.
Questions
Can an admin give a staff account the right to manage people?
No. Only admins can manage people, roles and system settings. Sasha does not let an admin give these rights to a staff or member account.
Why can a member not sign in to the Sasha web interface?
Members use Sasha from Claude. Chat in the Sasha web interface is for admin and staff accounts. A member connects Claude to Sasha instead.
I got a new role. Why does Claude not do more?
A connection keeps the permissions it had when you connected. To use your new role from Claude, connect Claude to Sasha again. A new shared project needs no new connection.
Can Claude reach a project that I cannot reach in Sasha?
No. Claude works with the access you approve when you connect, and never more than you have in Sasha.