Agent skill

Granola Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Configure enterprise role-based access control for Granola workspaces.

MITAuto-check passedBackend & APIs

Install Granola Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace granola-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/granola-enterprise-rbac .claude/skills/granola-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
granola-enterprise-rbac
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
667 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Configure enterprise role-based access control for Granola workspaces.

  • Works in 7 steps: Understand the Role Hierarchy → Permission Matrix → Map SSO Groups to Roles → …
  • Defining user roles
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Granola Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure enterprise role-based access control for Granola workspaces. Use when defining user roles, setting sharing permissions, configuring SSO group mappings, or implementing least-privilege access for meeting data. Trigger: "granola roles", "granola permissions", "granola access control", "granola RBAC", "granola admin roles".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Authorization and RBAC and Authentication. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Defining user roles
  • Setting sharing permissions
  • Configuring SSO group mappings
  • Implementing least-privilege access for meeting data

Example prompts

  • “granola roles”
  • “granola permissions”
  • “granola access control”
  • “/granola-enterprise-rbac”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Understand the Role Hierarchy
  2. Permission Matrix
  3. Map SSO Groups to Roles
  4. Configure Sharing Policies
  5. Implement Least Privilege
  6. Enable Audit Logging
  7. Handle User Lifecycle

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.granola.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Granola Enterprise Rbac loads about 2k tokens when it runs, and up to ~3.1k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 667 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 667 words, ~1,998 tokens.

Download SKILL.mdSave it as .claude/skills/granola-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
granola-enterprise-rbac
description
Configure enterprise role-based access control for Granola workspaces. Use when defining user roles, setting sharing permissions, configuring SSO group mappings, or implementing least-privilege access for meeting data. Trigger: "granola roles", "granola permissions", "granola access control", "granola RBAC", "granola admin roles".
allowed-tools
Read, Write, Edit
compatibility
Designed for Claude Code
version
1.13.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, granola, rbac, enterprise, security

Granola Enterprise RBAC

Overview

Configure role-based access control for Granola with SSO group mapping, per-workspace permissions, sharing policies, and audit logging. Granola's role hierarchy controls who can create, share, and manage meeting notes across the organization.

Prerequisites

  • Granola Enterprise plan ($35+/user/month)
  • Organization admin access
  • SSO configured (Okta, Azure AD, or Google Workspace)
  • SCIM provisioning enabled (recommended for automated role assignment)

Instructions

Step 1 — Understand the Role Hierarchy
Organization Owner (1-2 people)
  │   Full control: billing, SSO, org settings, all workspaces
  │
  ├── Workspace Admin (per department)
  │     Manage workspace: members, integrations, settings
  │     All member capabilities
  │
  ├── Team Lead
  │     View team analytics, manage folder structure
  │     All member capabilities
  │
  ├── Member (default role)
  │     Create notes, share internally, use integrations
  │
  ├── Viewer
  │     Read-only access to shared notes
  │     Cannot create or record meetings
  │
  └── Guest (external)
      Single workspace access, read-only
      Time-limited (30-day default expiration)
Step 2 — Permission Matrix
PermissionOwnerWS AdminLeadMemberViewerGuest
Record meetingsYesYesYesYesNoNo
Create notesYesYesYesYesNoNo
Share internallyYesYesYesYesNoNo
Share externallyYesYesPolicyPolicyNoNo
View shared notesYesYesYesYesYesYes
Manage integrationsYesYesNoNoNoNo
Manage membersYesYesNoNoNoNo
View analyticsYesYesYesNoNoNo
Configure retentionYesYesNoNoNoNo
Manage billingYesNoNoNoNoNo
Configure SSO/SCIMYesNoNoNoNoNo
Step 3 — Map SSO Groups to Roles

Configure in Organization Settings > Security > SSO > Group Mapping:

SSO Group (IdP)Granola WorkspaceGranola Role
engineering-allEngineeringMember
engineering-leadsEngineeringAdmin
sales-teamSalesMember
sales-managersSalesAdmin
product-teamProductMember
hr-teamHRMember
hr-directorsHRAdmin
executivesExecutiveAdmin
contractors-engEngineeringGuest

Multi-workspace membership: A user can belong to multiple workspaces with different roles:

  • Sarah Chen: Engineering (Member) + Product (Admin) + Executive (Viewer)
  • Mike Johnson: Sales (Admin) + Engineering (Guest for cross-team visibility)
Step 4 — Configure Sharing Policies

Set per-workspace sharing rules to control data flow:

Standard workspaces (Engineering, Product, Sales):

Workspace Settings > Sharing:
  Internal sharing: Automatic within workspace members
  Cross-workspace: Allowed with admin approval
  External sharing: Allowed with link expiration (30 days)
  Public links: Disabled

Confidential workspaces (HR, Executive):

Workspace Settings > Sharing:
  Internal sharing: Manual only (no auto-share)
  Cross-workspace: Disabled
  External sharing: Disabled
  Public links: Disabled
  Note visibility: Creator + explicitly added viewers only
Step 5 — Implement Least Privilege

Follow the principle of least privilege for role assignments:

  1. Default new users to Member — sufficient for 90% of use cases
  2. Promote to Admin only for workspace managers — IT leads, department heads
  3. Use Viewer for stakeholders who need to read notes but not create them
  4. Time-limit Guest access — 30-day default, renew explicitly
  5. Review access quarterly:
markdown
## Quarterly Access Review Checklist

- [ ] Pull current user list: Settings > Team
- [ ] Verify each user's role matches current job function
- [ ] Deactivate users who have left the organization
- [ ] Downgrade over-privileged users (Admin → Member where appropriate)
- [ ] Remove expired Guest accounts
- [ ] Verify SSO group mappings match current org chart
- [ ] Review sharing policy compliance per workspace
- [ ] Check audit logs for unusual access patterns
Step 6 — Enable Audit Logging

Enterprise audit logging captures:

EventWhat's Logged
User loginWho, when, from where (IP)
Note createdCreator, meeting, workspace
Note sharedSharer, recipient, method (Slack/Notion/link)
Note exportedWho exported, which note
Role changedAdmin, user affected, old role → new role
Integration connected/disconnectedWho, which integration
Workspace settings changedAdmin, what changed

Access audit logs: Organization Settings > Security > Audit Log

Export audit logs for SIEM integration (Enterprise):

  • Granola can export audit events to external systems
  • Contact Granola support for Splunk/Datadog/SIEM integration
Show full SKILL.md (250 more words)Show less
Step 7 — Handle User Lifecycle

Onboarding:

  1. User added to SSO group → SCIM provisions account → JIT assigns workspace + role
  2. First login: SSO authenticates, Granola provisions based on group mapping
  3. User can immediately record meetings in assigned workspaces

Role change:

  1. Update SSO group membership in IdP
  2. SCIM sync updates Granola role (within sync interval, typically 1-15 min)
  3. Or manually: Workspace Settings > Members > change role

Offboarding:

  1. Disable user in IdP → SCIM deactivates Granola account
  2. User loses access immediately
  3. Their shared notes remain visible to workspace members
  4. Their private notes are inaccessible (retained per retention policy)
  5. Reassign ownership of shared folders if needed

Output

  • Role hierarchy defined and documented
  • SSO group mappings configured for automated provisioning
  • Per-workspace sharing policies enforced
  • Audit logging enabled with SIEM export (if applicable)
  • User lifecycle procedures (onboard/offboard) established
  • Quarterly access review cadence scheduled

Error Handling

ErrorCauseFix
User can't access workspaceWrong SSO groupVerify IdP group membership
External sharing blocked unexpectedlyWorkspace policy overrideReview workspace sharing settings
Guest access expired30-day time limitRe-invite the guest or extend expiration
SCIM sync delayedIdP sync interval too longTrigger manual sync in IdP, or adjust interval
Orphaned accounts after terminationSCIM deprovisioning not configuredEnable deprovisioning in SCIM settings

Examples

scope=staging-calendar; mapping_rev=42; owner=platform-ops; allow_probe=pass; deny_probe=pass; sync=2026-08-27T14:00Z; rollback=rev41 proves the boundary without disclosing attendee groups.

Resources

Next Steps

Proceed to granola-migration-deep-dive for migrating from other meeting note tools.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/granola-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Granola Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Granola Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Granola Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS61810 repos~4.4kAutomated safety check: PassNone
Configuration Cryptogreenpau/caddy-security2.3k—~3.5kAutomated safety check: PassApache-2.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Bkend Authww-w-ai/bkit-claude-code601—~937Automated safety check: NotesApache-2.0

Similar skills

  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Bkend Auth

    ww-w-ai/bkit-claude-code

    bkend.ai authentication — email/social login, JWT tokens, RBAC, session management.

    601 GitHub stars~937 tokensUpdated 14 days ago
    Backend & APIsAuto-check: notes
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    756 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Granola Enterprise Rbac

What does Granola Enterprise Rbac do?

Configure enterprise role-based access control for Granola workspaces. Granola Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Configure enterprise role-based access control for Granola workspaces.

When should I use Granola Enterprise Rbac?

Granola Enterprise Rbac fits situations like: defining user roles; setting sharing permissions; configuring SSO group mappings; implementing least-privilege access for meeting data.

How do I install Granola Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/granola-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/granola-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Granola Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/granola-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/granola-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Granola Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill granola-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/granola-enterprise-rbac, .gemini/skills/granola-enterprise-rbac, .github/skills/granola-enterprise-rbac and .opencode/skills/granola-enterprise-rbac in your project.

What does Granola Enterprise Rbac need to run?

SKILL.md names no scripts, command-line tools or credentials: Granola Enterprise Rbac is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code.

Does Granola Enterprise Rbac access the network?

SKILL.md names 1 domain. As links in the text: docs.granola.ai. This is read from the text; nothing was executed.

Is Granola Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Granola Enterprise Rbac use?

Granola Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Granola Enterprise Rbac use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Granola Enterprise Rbac?

Skills that share tags, products or a category with Granola Enterprise Rbac: Cognito (itsmostafa/aws-agent-skills, 1.2k stars), Auth Implementation Patterns (ynulihao/AgentSkillOS, 618 stars), Configuration Crypto (greenpau/caddy-security, 2.3k stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Granola Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.