Skip to content

Groups & AI Models

Administrators only.

Settings → Groups

Groups make it possible to organize users and assign permissions in bundles. Instead of configuring access rights for each user individually, you assign them to a group, and all members automatically receive the same rights.

Typical use cases:

  • Marketing team: access to the marketing knowledge base and marketing tools
  • Sales: access to product information and CRM integration
  • Management: access to all knowledge bases

The table shows all groups with:

  • Name: clickable to open the detail page
  • Description: purpose of the group
  • Members: number of members
  • Created on: date of creation
  1. Click “Create group”
  2. Enter a name (required, max. 100 characters), e.g. “Marketing team”
  3. Optionally add a description (max. 500 characters)
  4. Click “Create”

You are automatically redirected to the detail page of the new group, where you can add members.

Click a group in the overview to open the detail page.

  • Change name
  • Change description

Click “Save” to apply the changes.

Add member:

  1. Open the picker for adding members in the “Members” area
  2. The list shows the people in your workspace right away. You only need to type if you want to narrow it down
  3. Select the user, they are added to the group immediately

Remove member:

Click the remove button next to the member’s name.

Some groups are labeled as a System group. They automatically contain all members of the workspace and cannot be edited or deleted.

You recognize system groups by the “System group” label in the actions column. They are not clickable.

Note: The system group “Alle Mitglieder” is particularly useful if you want to grant a knowledge base or a tool access to all users without adding each one individually.

A group controls not only access to knowledge bases and tools, but also what its members are allowed to do, for example create agents, connect integrations, connect data sources or manage billing. You grant these permissions per group rather than assigning them to individual users.

Open a group and scroll to the “Permissions” area. There you find all grantable rights, grouped by area:

  • Agents – create and share agents
  • Knowledge – create knowledge bases
  • Integrations – connect system templates and your own MCP servers
  • Skills – create and upload your own skills and connect them to third-party systems
  • Data sources – connect OneDrive, SharePoint, mailbox (Microsoft 365) and file server
  • Models & costs – which price tiers the group may pick in chat, and whether it can use the AI credit
  • Administration – manage billing and view usage analytics

Each right has a toggle, and the change is saved immediately. Permissions add up across all of a user’s groups: whoever is in several groups receives the sum of all rights.

Most rights are active for everyone by default, because they are granted through the system group “Alle Mitglieder”. If a right is already available to a regular group through it, 9brains shows the note ”✓ Already granted to all users”. You don’t need to do anything there.

If you want to remove a default right from everyone, open the system group “Alle Mitglieder” and switch the right off there. Because this affects every user, 9brains asks for confirmation first.

Some rights are not granted by default and are initially reserved for administrators, for example “Manage billing” and “View usage analytics”. You can delegate them to a specific group without giving its members full administrator rights.

Example: giving the accounting team access to billing

  1. Create a group, e.g. “Accounting”
  2. Add your colleagues from accounting as members
  3. In the “Permissions” area, open the Administration category and enable “Manage billing”

The group’s members now see Settings → Billing and can manage invoices, subscription and payment details, all without being an administrator. In the same way, “View usage analytics” delegates access to the usage statistics, for example to a controlling team.

Note: Administrators automatically hold all rights. The Models & costs category is the exception: those rights apply to administrators themselves as well, so that a cost limit really covers everyone. Some rights additionally require a certain license (e.g. Business): if it is not present in the workspace, the right stays visible but is greyed out and marked with a license note.

Blocking expensive models for individual groups

Section titled “Blocking expensive models for individual groups”

Every AI model carries a cost category from € to €€€€. In the Models & costs category you decide per group which of the three more expensive tiers its members may select in chat:

  • Balanced models (€€) – a good balance of quality and consumption
  • Expensive models (€€€) – use up the quota considerably faster
  • Very expensive models (€€€€) – use up the quota fastest

The economical tier (€) deliberately has no switch: it is always available to everyone. That keeps every group able to work, however you set the other three.

All three tiers are released for everyone to begin with. Switch a tier off and its models disappear from the model picker in chat for the affected users. An ongoing chat that was running on a blocked model switches to an allowed one the next time it is opened.

Example: only one team may use the flagship models

  1. Open the system group “All members” and switch “Very expensive models (€€€€)” off there
  2. Create a group, e.g. “Research”, and add the colleagues who need it
  3. Enable “Very expensive models (€€€€)” in that group

Because rights add up across all of a user’s groups, that is all it takes: the “Research” group keeps the flagship models, everyone else no longer sees them.

Unlike the other permissions, this also applies to you as an administrator: take a price tier away from everyone and it is gone for you too. A cost limit that exempts the administrators of all people would defeat its own purpose. You cannot lock yourself out either, because the switch stays visible to you and you can release the tier again at any time, for yourself or for a group.

Guests from other workspaces follow your settings: an external partner or colleague working in your workspace automatically belongs to “All members” there and therefore has exactly the price tiers you give that group. Conversely, your own people working in someone else’s workspace follow whatever is configured there.

Since the control works on the price tier rather than on individual model names, there is nothing to maintain when 9brains adds new models. A new model falls into its price tier automatically and follows the setting you already made.

What about agents? An agent has a fixed model, chosen by whoever built it. The lockout applies when the agent is configured: whoever pins a model or picks a quality tier can only do so with price tiers enabled for them. That covers every route, including creating an agent from the chat and duplicating someone else’s.

Agents configured earlier stay as they are when you switch a tier off later. A colleague for whom the tier is blocked then chats with that agent on an allowed model instead of running into an error. The agent keeps its own setting, and whoever has the tier keeps working with it unchanged.

Who keeps working on the credit once the allowance is used up

Section titled “Who keeps working on the credit once the allowance is used up”

When a user’s licence allowance is used up, their usage continues on the purchased AI credit, provided there is any. The “Use AI credit” right decides who that applies to.

Take the right away from a group and usage ends with the quota for its members: they keep working with the cheapest models only, while colleagues who hold the right carry on with the credit as before. That way you reserve the credit for the people who really need it, instead of leaving it to whoever happens to chat first.

The right applies at both limits: a user’s personal quota and the shared workspace pool. So someone without it is put on the cheapest models even when their own quota is still open but the workspace pool has run dry.

Trying out projects with a small circle first

Section titled “Trying out projects with a small circle first”

In the Projects category, the right “Use projects” controls who may create projects and work in them. Like the other default rights, it is active for everyone to begin with.

If you want to try projects out in one team first, proceed as follows:

  1. Open the system group “Alle Mitglieder” and switch “Use projects” off there
  2. Create a group, e.g. “Project pilot”, and add the colleagues who should test it
  3. Enable “Use projects” in that group

For everyone else, the entire Projects area disappears: the sidebar entry, the project overview and the project features in the chat as well. Anyone who receives the right later sees the area after the next page reload.

  1. Click “Delete” in the actions menu of the group
  2. Confirm the deletion in the dialog that appears

Warning: Deleting a group cannot be undone. All permissions granted via the group are also removed.

Administrators only.

Settings → AI models

Here you define which AI models are available to users in your workspace. Disabled models can no longer be selected for chats.

At the top of the page you see: “X of Y models enabled”

The default model is preselected automatically for new chats. You can:

  • Use system default: 9brains automatically selects the best available model
  • Set a specific model: choose from the list of enabled models

Note: Users can select a different model in each chat, as long as it is enabled. The default model only determines the preselection.

The following notice is displayed on the page:

“All AI models are integrated so that they do not store any data and do not use any data for training.”

The models are grouped by provider (e.g. Anthropic, OpenAI, Google, Mistral). For each provider you see a card with all available models.

Each model shows:

  • Name of the model
  • Location: where the model is operated (e.g. EU, USA)
  • Speed: relative response speed
  • Quality: relative response quality

Each model shows a cost category from € to €€€€ indicating how heavily it consumes the monthly quota. Very expensive models (€€€€) use up the quota fastest, economical models (€) slowest.

The cost category also lets you control per user group how expensive the models may be that its members can select. See Blocking expensive models for individual groups.

Watch for the colored labels on each model:

| Label | Meaning | | ---------------- | -------------------------------------------------------------------------------------------------------------- | | EU-Sovereign | The model is hosted on EU-sovereign infrastructure. Full data control within the EU | | GDPR | GDPR-compliant. Data is processed exclusively in the EU. No data transfer to third countries | | GDPR (DPF) | GDPR-compliant via the EU-US Data Privacy Framework. Data may be processed in the US, but is legally protected | | Global | Not usable in a GDPR-compliant way. No EU server location and no DPF certification |

Tip: If your company places particular emphasis on data protection, only enable models with the EU-Sovereign, GDPR, or GDPR (DPF) label.

Each model has a toggle to enable or disable it. The change takes effect immediately.

  • Enable: the model is available to all users in the chat
  • Disable: the model disappears from the selection. Running chats that use this model are not affected

Administrators only.

Settings → AI models

In addition to the chat models, you also manage the image models here. These are used by image generation and image editing in the chat.

Just like the chat default model, you can set a default image model:

  • Use system default: 9brains automatically selects a suitable model
  • Set a specific model: choose from the list of enabled image models

You can also set a separate default model for image editing. This model is used when users want to modify existing images, for example replacing backgrounds, removing objects, or combining elements from multiple images (compositing).

  • Use system default: uses the system-wide configured image editing model
  • Set a specific model: choose a model that delivers particularly good results for image editing

Note: Users can request a different image model in the chat, as long as it is enabled. For multi-image requests (combining several images), a compatible model is selected automatically.

Just like the chat models, every image model has a toggle to enable or disable it. Disabled image models are not available in the chat.

For more information on using the image features, see Create & edit images.

Can I also change my personal settings from the chat?

Section titled “Can I also change my personal settings from the chat?”

No. The personal settings can only be changed via the settings page. They then apply to all future chat messages.

No. Your settings (theme, form of address, tone, etc.) only apply to you personally and are not visible to others.

What happens when an administrator enforces MFA?

Section titled “What happens when an administrator enforces MFA?”

All users who have not yet set up MFA are prompted to do so within the defined deadline. After the deadline expires, access without MFA is no longer possible.

No. Your role (User or Admin) can only be changed by another administrator. You cannot adjust your own role.

The user loses access to the workspace. Their previous chat history and contributions to knowledge bases are preserved.

No. Deleting a group is irreversible. You would have to create the group again and reassign the members.

What is the difference between role and license type?

Section titled “What is the difference between role and license type?”

The role (User/Admin) determines which management sections you see. The license type (Business/Pro/Knowledge Only) determines which features you can use, for example integrations and tools are only available with the Business license.

At least one model must be enabled for the chat to work. If you only want to allow GDPR-compliant models, disable all models with the “Global” label.

Do my employees automatically use the default model?

Section titled “Do my employees automatically use the default model?”

The default model is only the preselection for new chats. Users can switch to any other enabled model in the model picker in the chat at any time.