Model access for users and groups
Renta keeps an access list for every data model that AI agents can query. The list names the workspace members and groups that can describe and query the model through AI agents and the Renta API.
A new model is closed by default. Only its creator and the workspace owners can use it until an owner adds other people.
Before you begin
Check the following before you change an access list.
- Owner role.
Only workspace owners change access lists. Members can view them. To check roles, see Team & Roles. - Model scope.
A model has an access list when its scope is AI agents only or AI agents & Reverse ETL. A model with the Reverse ETL only scope is not available to AI agents, so it has no list to manage. - Members and groups.
You can add only members who have joined the workspace. To grant a model to several people at once, create a group first.
Who can use a model
Renta checks workspace membership and the access list on every request to a model. The following table shows how each kind of access works.
| Who | Access |
|---|---|
| Workspace owners | Every model in the workspace. Owners do not need to be on the list. |
| Model creator | Renta adds the creator to the list when the model is created. |
| Members listed in Users | Direct access to this model. |
| Members of a group listed in Groups | Access through the group. A person you add to the group later gets access to the model without any change to the list. |
| Other members | No access. The model is missing from list_models, and requests to it return the Model access denied error. |
Grant access from the model list
You need the owner role in the workspace.
- In the left sidebar, click Context layers.
- Find the model and click its cell in the Access column. You can also open the row menu and select Access.
The Access column shows who can use each model: the avatars of listed users and groups, or Owners only when nobody else is listed. A dash means the model has the Reverse ETL only scope.

The Access panel opens with the model name in the header.
- In the Users card, select the members who need direct access.
- In the Groups card, select the groups. Every member of a selected group can use the model.
- Click Save.
Selected users and groups appear below each picker. To remove one before you save, click the cross next to it.

Manage access on the model page
The Access tab of a model shows the same list with more detail. Use it to review who has access and why.

- In the left sidebar, click Context layers and open the model.
- Open the Access tab (1).
- In the Users card, click Add users (2), select the members, and then click Add users in the panel.
- In the Groups card, click Add groups (3), select the groups, and then click Add groups in the panel.
- Click Save changes (4).
Changes on this tab apply only after you click Save changes.
The Add groups panel lists the groups that are not on the model yet. Select a group (1) and click Add groups (2). The Add users panel works the same way.

The Access column of the Users card shows why each person can use the model.
| Label | Meaning |
|---|---|
| Always | A workspace owner. Owners can use every model and cannot be removed from the list. |
| Direct | A member added to this model personally. |
| Former member | A person who is on the list but is no longer a member of the workspace. They cannot use the model. Remove the row to clean up the list. |
Members who have access only through a group are not listed in the Users card. To see them, click the group in the Groups card and check its member count, or open the group on the Team members page.
Remove access
Remove a user or a group on the Access tab of the model.
- Click the row of the user or the group. The User access or Group access panel opens.
- Click Remove access.
- Click Save changes.

A removed user stays in the workspace and no longer sees or queries the model. Members of a removed group lose access unless they are also listed in the Users card.
You cannot remove your own access or the access of another owner.
Set access when you create a model
When the scope of a new model includes AI agents, the model wizard adds the Access step after Measures. Your account is already selected as the creator.
- Owners.
Add users and groups on this step, the same way as on the Access tab. - Members.
A member creates the model with access for themselves only. An owner can add other people later.
What happens when the team changes
Renta updates access when the workspace team changes. You do not need to edit the lists by hand.
| Change | Result |
|---|---|
| A member leaves the workspace | They lose access to every model. Renta removes them from the access lists. |
| A person is added to a group | They get access to every model the group is listed on. |
| A person is removed from a group | They lose the access they had through that group. |
| A group is deleted | Renta removes the group from every access list. Its members lose access unless they are listed directly. |
| A member becomes an owner | They can use every model in the workspace. |
Access lists in the REST API and MCP
The data model API returns and accepts the same list in the model_access field. Requests need a Renta API token with permissions in the Context Layer category.
| Request | Permission | What it does with the list |
|---|---|---|
GET /v1/data_model?model_id=MODEL_ID | Read | Returns model_access with user_ids and group_ids. |
PATCH /v1/data_model | Update | Replaces the list with the one you send. Owner role required. If you leave model_access out, the list stays as it is. |
POST /v1/data_model | Create | Creates the model and adds the creator to the list. Adding other users or groups requires the owner role. |
The list is replaced as a whole. Send every user and group that keeps access, not only the new ones.
curl -X PATCH "https://api.eu.renta.im/v1/data_model" \
-H "Authorization: Bearer YOUR_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"model_id": "MODEL_ID",
"model_access": {
"user_ids": ["USER_ID"],
"group_ids": ["GROUP_ID"]
}
}'In the Renta MCP Server, the manage_data_models tool accepts the same model_access object when it creates a model.
Related pages
The following pages describe groups, roles, and the models that the access list protects.
Ready to get started?
Build your data pipeline today or get a personalized demo. Start free!
Need help?
Get expert support to ensure your project succeeds. We're here to help!
Feature requests?
Help shape our product! Share your ideas for new features and integrations.