> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getcargo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Upsert user permissions

> Grant permissions on a resource to users



## OpenAPI

````yaml https://api.getcargo.io/openapi.json post /workspaceManagement/users/permissions
openapi: 3.1.0
info:
  title: Cargo API
  version: 1.0.0
  description: Cargo Platform API v1
servers:
  - url: https://api.getcargo.io/v1
    description: Cargo API
security:
  - bearerAuth: []
paths:
  /workspaceManagement/users/permissions:
    post:
      tags:
        - Workspace Management - Users
      summary: Upsert user permissions
      description: Grant permissions on a resource to users
      requestBody:
        required: true
        content:
          application/json:
            schema:
              allOf:
                - anyOf:
                    - type: object
                      properties:
                        userUuids:
                          type: array
                          items:
                            type: string
                        emails:
                          type: array
                          items:
                            type: string
                      required:
                        - userUuids
                    - type: object
                      properties:
                        emails:
                          type: array
                          items:
                            type: string
                        userUuids:
                          type: array
                          items:
                            type: string
                      required:
                        - emails
                - type: object
                  properties:
                    action:
                      type: string
                      enum:
                        - ai:*
                        - ai:read
                        - ai:write
                        - ai:agent:*
                        - ai:agent:read
                        - ai:agent:write
                        - ai:mcpServer:*
                        - ai:mcpServer:read
                        - ai:mcpServer:write
                        - billing:*
                        - billing:read
                        - billing:write
                        - connection:*
                        - connection:read
                        - connection:write
                        - context:*
                        - context:read
                        - context:write
                        - domainManagement:*
                        - domainManagement:read
                        - domainManagement:write
                        - hosting:*
                        - hosting:read
                        - hosting:write
                        - hosting:app:*
                        - hosting:app:read
                        - hosting:app:write
                        - hosting:worker:*
                        - hosting:worker:read
                        - hosting:worker:write
                        - orchestration:*
                        - orchestration:read
                        - orchestration:write
                        - orchestration:workflow:*
                        - orchestration:workflow:read
                        - orchestration:workflow:write
                        - revenueOrganization:*
                        - revenueOrganization:read
                        - revenueOrganization:write
                        - segmentation:*
                        - segmentation:read
                        - segmentation:write
                        - storage:*
                        - storage:read
                        - storage:write
                        - content:*
                        - content:read
                        - content:write
                        - content:file:*
                        - content:file:read
                        - content:file:write
                        - systemOfRecordIntegration:*
                        - systemOfRecordIntegration:read
                        - systemOfRecordIntegration:write
                        - workspaceManagement:*
                        - workspaceManagement:read
                        - workspaceManagement:write
                        - workspaceManagement:folder:*
                        - workspaceManagement:folder:read
                        - workspaceManagement:folder:write
                    resourceUuid:
                      type: string
                      format: uuid
                      pattern: >-
                        ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-4[0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12})$
                  required:
                    - action
                    - resourceUuid
              title: Request body
              description: Request body schema.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties: {}
                additionalProperties: false
        '400':
          description: Bad request
        '401':
          description: Unauthorized
        '404':
          description: Not found
        '500':
          description: Internal server error
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````