Projects and sharing
A project groups related workflows, chats, integrations, and variables, and is the unit of access control in Helios.
A project groups related work: workflows, chats, integrations, variables and secrets.
More importantly, a project is the unit of access control. Resources inside it inherit their access from it, so granting a teammate access to a project grants them access to everything in it - which is almost always what you want.
Your personal project
Every user gets a Personal project in each organization they belong to. It is restricted to you and it's where ad-hoc chats land. Use it to try things; move work into a shared project when it matters to someone other than you.
Creating a project
Any member can create a project. The creator becomes its admin.
Give it a name that describes the work. "support triage" ages better than "support team's stuff".
Sharing a project
Open the project's permissions to control who can reach it. There are two dials.
Visibility decides the baseline:
- Restricted - only people you grant access to, explicitly.
- Organization - everyone in the organization gets access, at a role you choose.
Grants give a specific person, group, or service account a specific
role on the project: viewer, operator, editor, or admin.
A grant can expire after a day, a week, or a date you choose. An explicit grant adds to the baseline.
The common shape is an organization-visible project at the operator role, so everyone can see the
agents and run them, with editor granted to the handful of people who maintain the prompts.
A restricted project must always keep at least one explicit admin. Helios won't let you remove the last one.
Sharing integrations
Integrations have their own visibility, managed the same way. Connect GitHub once at organization visibility and every project's agents can use it.
Credentials are never exposed by sharing an integration. Users of a shared integration can have
agents act through it. Only an admin of the integration can read the credential behind it.
Sharing a chat transcript
Sharing a chat is a different thing entirely - it produces a public link to a read-only transcript, up to a message you choose. It doesn't grant access to Helios, and anyone with the link can read it. Use it to show a colleague what an agent did. To work together, share the project.
Sharing databases and MCP servers
Database connections and MCP servers are shared the same way as integrations. Each one belongs to one or more projects and can carry its own grants.
Related
- Roles and permissions - what each role can do.
- SSO and SCIM - provisioning people into the organization.
Last updated on
Projects and access
Pick the active project with project use, HELIOS_PROJECT, or --project. Share resources, audit access, and manage groups and service accounts from the CLI.
Roles and permissions
Helios has two layers of access control. An organization role says what you can create. A resource role says what you can do to a specific project, workflow, chat, or integration.