Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure Clay workspace roles, team access control, and credit budget allocation. Use when managing team access to Clay tables, setting per-user credit budgets, or configuring workspace-level permissions for Clay. Trigger with phrases like "clay SSO", "clay RBAC", "clay enterprise", "clay roles", "clay permissions", "clay team access", "clay workspace".
.claude/skills/jeremylongshore-clay-enterprise-rbac/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-11 | ✗→✓ | ▲ Improved | 7% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 29% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 11% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 38% | 0% |
Control access to Clay tables, enrichment credits, and integrations at the team level. Clay uses a workspace model where team members are assigned Admin, Member, or Viewer roles. This skill covers role assignment, credit budget allocation, API key isolation, and audit procedures.
Clay has three built-in roles with fixed permissions:
| Capability | Admin | Member | Viewer | |------------|-------|--------|--------| | Manage workspace members | Yes | No | No | | Manage billing and credits | Yes | No | No | | Create/delete tables | Yes | Yes | No | | Run enrichments | Yes | Yes | No | | Configure integrations | Yes | No | No | | Export data | Yes | Yes | Yes | | View all tables | Yes | Yes | Yes |
Recommended role assignments:
yamlroles: admin: assign_to: - Revenue Operations Lead - GTM Engineering Lead why: "Controls billing, integrations, and team access" member: assign_to: - SDRs building prospect lists - Growth engineers building pipelines - Marketing ops running enrichment campaigns why: "Can create tables and run enrichments but can't change billing or integrations" viewer: assign_to: - Sales managers reviewing lead quality - Executives checking pipeline metrics - Finance reviewing credit usage why: "Read-only access to enriched data and exports"
In Clay UI: Settings > Members > Invite
Best practices:
Create separate API keys for each downstream system to enable independent revocation:
yamlapi_keys: crm-sync-prod: purpose: "HubSpot CRM sync from Clay" used_by: "HTTP API column in Outbound Leads table" rotation: quarterly outbound-instantly: purpose: "Push qualified leads to Instantly.ai" used_by: "HTTP API column for outreach" rotation: quarterly internal-dashboard: purpose: "Pull enrichment metrics for internal dashboard" used_by: "Cron job reading Clay table stats" rotation: quarterly ci-testing: purpose: "Integration tests in CI pipeline" used_by: "GitHub Actions workflow" rotation: on-demand
Since Clay doesn't have per-user credit budgets natively, implement controls at the table level:
typescript// src/clay/budget-controls.ts interface TableBudget { tableId: string; tableName: string; maxRows: number; // Prevent over-enrichment autoEnrich: boolean; // Control automatic processing owner: string; // Team member responsible monthlyCreditsEstimate: number; } const TABLE_BUDGETS: TableBudget[] = [ { tableId: 'outbound-leads', tableName: 'Outbound Leads', maxRows: 5000, autoEnrich: true, owner: 'sdr-team@company.com', monthlyCreditsEstimate: 3000, }, { tableId: 'event-attendees', tableName: 'Event Attendees', maxRows: 1000, autoEnrich: false, // Manual trigger only owner: 'marketing@company.com', monthlyCreditsEstimate: 600, }, { tableId: 'inbound-leads', tableName: 'Inbound Leads', maxRows: 2000, autoEnrich: true, owner: 'growth-eng@company.com', monthlyCreditsEstimate: 1200, }, ]; function auditBudgets(budgets: TableBudget[]): void { const totalEstimate = budgets.reduce((sum, b) => sum + b.monthlyCreditsEstimate, 0); console.log(`=== Clay Credit Budget Audit ===`); for (const b of budgets) { console.log(` ${b.tableName}: ${b.maxRows} rows, ~${b.monthlyCreditsEstimate} credits/mo (owner: ${b.owner})`); } console.log(` Total monthly estimate: ${totalEstimate} credits`); }
markdown## Clay Workspace Access Audit Checklist - [ ] Review all workspace members — remove former employees - [ ] Verify role assignments match current job functions - [ ] Check API key usage — revoke unused keys - [ ] Review table access — archive unused tables - [ ] Audit credit usage by table — identify waste - [ ] Verify provider API key connections are current - [ ] Update API key rotation log - [ ] Review and update table row limits - [ ] Check webhook submission counts (approaching 50K?) - [ ] Document any new tables or integrations added
| Issue | Cause | Solution | |-------|-------|----------| | 403 on table creation | User is Viewer role | Upgrade to Member role | | Credits exhausted mid-campaign | No budget cap on table | Set max_rows on table | | Integration key rejected | Key was revoked | Generate new key, update integration config | | Unauthorized data export | Viewer exported sensitive data | Review export audit log | | Former employee still has access | No offboarding process | Immediate removal on departure |
For migration strategies, see clay-migration-deep-dive.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 18,056 | 9,838 | -46% | 1 | 1 | 0% | 2,705 | 3,006 | +11% | 0 | 0 | — |
case-02 | fail→fail | 23,644 | 18,590 | -21% | 1 | 1 | 0% | 4,316 | 5,203 | +21% | 0 | 0 | — |
case-03 | fail→fail | 20,184 | 17,376 | -14% | 1 | 1 | 0% | 3,139 | 4,350 | +39% | 0 | 0 | — |
case-04 | pass→pass | 13,684 | 9,650 | -29% | 1 | 1 | 0% | 2,103 | 2,899 | +38% | 0 | 0 | — |
case-05 | pass→pass | 5,790 | 8,230 | +42% | 1 | 1 | 0% | 927 | 2,022 | +118% | 0 | 0 | — |
case-06 | pass→pass | 14,692 | 8,349 | -43% | 1 | 1 | 0% | 2,063 | 2,622 | +27% | 0 | 0 | — |
case-07 | fail→pass | 12,292 | 8,740 | -29% | 1 | 1 | 0% | 1,991 | 2,652 | +33% | 0 | 0 | — |
case-08 | pass→pass | 14,689 | 7,483 | -49% | 1 | 1 | 0% | 2,342 | 2,643 | +13% | 0 | 0 | — |
case-09 | pass→pass | 14,088 | 10,441 | -26% | 1 | 1 | 0% | 2,246 | 2,884 | +28% | 0 | 0 | — |
case-10 | pass→pass | 16,908 | 16,926 | +0% | 1 | 1 | 0% | 2,623 | 4,301 | +64% | 0 | 0 | — |
case-11 | fail→pass | 16,557 | 10,316 | -38% | 1 | 1 | 0% | 2,867 | 3,081 | +7% | 0 | 0 | — |
case-12 | pass→pass | 14,398 | 14,937 | +4% | 1 | 1 | 0% | 2,492 | 4,069 | +63% | 0 | 0 | — |
case-13 | pass→pass | 9,118 | 3,940 | -57% | 1 | 1 | 0% | 1,563 | 2,087 | +34% | 0 | 0 | — |
case-14 | fail→fail | 16,579 | 13,427 | -19% | 1 | 1 | 0% | 2,478 | 3,675 | +48% | 0 | 0 | — |
case-15 | pass→pass | 12,252 | 8,076 | -34% | 1 | 1 | 0% | 1,978 | 2,736 | +38% | 0 | 0 | — |
case-16 | fail→pass | 15,066 | 10,193 | -32% | 1 | 1 | 0% | 2,318 | 2,995 | +29% | 0 | 0 | — |
case-17 | pass→pass | 10,239 | 4,916 | -52% | 1 | 1 | 0% | 1,044 | 2,094 | +101% | 0 | 0 | — |
case-18 | pass→pass | 13,119 | 7,365 | -44% | 1 | 1 | 0% | 1,756 | 2,320 | +32% | 0 | 0 | — |
case-19 | pass→pass | 19,461 | 13,411 | -31% | 1 | 1 | 0% | 2,167 | 2,713 | +25% | 0 | 0 | — |
case-20 | pass→pass | 6,405 | 4,948 | -23% | 1 | 1 | 0% | 1,240 | 2,229 | +80% | 0 | 0 | — |
case-21 | pass→pass | 15,233 | 10,159 | -33% | 1 | 1 | 0% | 2,580 | 3,262 | +26% | 0 | 0 | — |
case-22 | pass→pass | 14,654 | 10,662 | -27% | 1 | 1 | 0% | 2,332 | 2,991 | +28% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.