Welcome to Zuora Product Documentation

Explore our rich library of product information

User Permissions and Roles

Learn how Zuora AI enforces your existing permissions, approvals, and tenant isolation.

User-level access

After Zuora AI is enabled at the tenant level, user access depends on the Zuora application and the user’s permissions.

ProductAccess behavior
Zuora BillingWhen AI is enabled for the tenant, users can access Zuora AI. Each user’s effective access is determined by the tenant-level AI mode and the user’s existing Zuora permissions.
Zuora RevenueUsers must have the AI permission explicitly enabled. Users without this permission cannot see the Zuora AI interface, regardless of the tenant-level AI setting.

Role-level AI permissions in Zuora Billing

In Zuora Billing, administrators control access to AI capabilities by assigning AI permissions to platform roles.

Use Read AI

The Use Read AI permission controls whether users in a role can use read-only AI capabilities, such as asking questions, querying data, and viewing AI-generated summaries.

If a role does not have the Use Read AI permission, users who are assigned to that role cannot use read-only AI capabilities, including Zuora AI chat and narrative summaries.

Use Supervised AI

The Use Supervised AI permission controls whether users in a role can use Supervised mode. For information about limiting Supervised mode to specific roles, see Limit Supervised mode to specific roles.

Role-level AI permissions in Zuora Revenue

In Zuora Revenue, administrators control AI access and capabilities through role privileges.

AI permission levels

You can assign an AI permission level in Setups > Security > Roles > Role Privileges:

  • The Read AI permission allows users to view AI output.

  • The Supervised AI permission allows users to interact with and apply AI suggestions.

Revenue write-action permissions

The Revenue Actions category in Role Privileges provides individual enable or disable controls for each supported AI write action. The overall AI write permission must be enabled before any write action is available. The individual Revenue Actions settings then determine which write actions users in the role can access.

This configuration lets you enable only the write actions that are appropriate for a role without enabling every supported Zuora Revenue write action.

Permission checks before an AI request

Zuora AI checks your permissions for an operation before asking you to provide inputs or approve the action. If you do not have access to the requested capability, Zuora AI informs you before it collects additional information or requests confirmation.

How existing permissions apply

Zuora AI uses the same API layer and role-based access control as manual actions in Zuora.

For example, if you do not have permission to post an invoice in the standard Zuora UI, you cannot post an invoice through Zuora AI.

Zuora AI does not bypass permissions, segregation of duties, or approval workflows. You can view data and perform actions only for the Zuora products and objects that you have permission to access.

Approval for write actions in the Zuora AI product experience

Zuora AI does not perform write actions automatically. When a write action is available, Zuora AI shows the action details and waits for your approval. You can review the proposed action before you confirm or decline it. For more detailed information, see Supervised mode for Zuora AI.

Authentication and tenant isolation

Zuora AI uses Zuora's existing authentication and authorization framework. Requests are authenticated through OneID and OAuth 2.0 by the Zuora API Gateway. The API Gateway validates the token and enforces the caller's tenant- and role-scoped access. Any IP-based restrictions that apply to your Zuora OneID access also apply to Zuora AI through the existing API Gateway policy layer.

Zuora AI operates only on data from the tenant associated with the request. It does not provide cross-tenant access or share data between tenants. Service accounts are managed through Zuora's standard IAM practices.

Administrator logging

Zuora AI logs agent interactions with the user, tenant, and timestamp in Zuora's centralized logging and monitoring systems. Organization Administratorscan monitor these logs through Watch Tower. Log retention follows Zuora's standard log retention policy.