clay-enterprise-rbac
Manages team access, credit budgets, and role assignments for Clay workspaces.
Install
mkdir -p .claude/skills/clay-enterprise-rbac && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8647" && unzip -o skill.zip -d .claude/skills/clay-enterprise-rbac && rm skill.zipInstalls to .claude/skills/clay-enterprise-rbac
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Configure Clay workspace roles, team access control, and credit budgetKey capabilities
- →Assign workspace roles (Admin, Member, Viewer)
- →Isolate API keys by integration purpose
- →Implement table-level credit budget controls
- →Conduct quarterly access audits
- →Manage team member invitations
How it works
The skill utilizes a workspace model to manage access control, assigning specific roles to team members and implementing programmatic budget caps at the table level.
Inputs & outputs
When to use clay-enterprise-rbac
- →Configure SSO for Clay
- →Define team roles and permissions
- →Allocate per-user credit budgets
- →Set up workspace access controls
About this skill
Clay Enterprise RBAC
Overview
Control access to Clay tables, enrichment credits, and integrations at the team level. Clay uses a workspace model where team members are assigned Admin, Member, or Viewer roles. This skill covers role assignment, credit budget allocation, API key isolation, and audit procedures.
Prerequisites
- Clay Team or Enterprise plan
- Workspace admin privileges
- Understanding of team structure and data access needs
Instructions
Step 1: Define Role Matrix
Clay has three built-in roles with fixed permissions:
| Capability | Admin | Member | Viewer |
|---|---|---|---|
| Manage workspace members | Yes | No | No |
| Manage billing and credits | Yes | No | No |
| Create/delete tables | Yes | Yes | No |
| Run enrichments | Yes | Yes | No |
| Configure integrations | Yes | No | No |
| Export data | Yes | Yes | Yes |
| View all tables | Yes | Yes | Yes |
Recommended role assignments:
roles:
admin:
assign_to:
- Revenue Operations Lead
- GTM Engineering Lead
why: "Controls billing, integrations, and team access"
member:
assign_to:
- SDRs building prospect lists
- Growth engineers building pipelines
- Marketing ops running enrichment campaigns
why: "Can create tables and run enrichments but can't change billing or integrations"
viewer:
assign_to:
- Sales managers reviewing lead quality
- Executives checking pipeline metrics
- Finance reviewing credit usage
why: "Read-only access to enriched data and exports"
Step 2: Invite and Manage Team Members
In Clay UI: Settings > Members > Invite
Best practices:
- Use company email addresses (not personal)
- Start new members as Viewers until they complete Clay training
- Audit member list quarterly -- remove departed employees immediately
Step 3: Isolate API Keys by Integration
Create separate API keys for each downstream system to enable independent revocation:
api_keys:
crm-sync-prod:
purpose: "HubSpot CRM sync from Clay"
used_by: "HTTP API column in Outbound Leads table"
rotation: quarterly
outbound-instantly:
purpose: "Push qualified leads to Instantly.ai"
used_by: "HTTP API column for outreach"
rotation: quarterly
internal-dashboard:
purpose: "Pull enrichment metrics for internal dashboard"
used_by: "Cron job reading Clay table stats"
rotation: quarterly
ci-testing:
purpose: "Integration tests in CI pipeline"
used_by: "GitHub Actions workflow"
rotation: on-demand
Step 4: Set Credit Budget Controls
Since Clay doesn't have per-user credit budgets natively, implement controls at the table level:
// src/clay/budget-controls.ts
interface TableBudget {
tableId: string;
tableName: string;
maxRows: number; // Prevent over-enrichment
autoEnrich: boolean; // Control automatic processing
owner: string; // Team member responsible
monthlyCreditsEstimate: number;
}
const TABLE_BUDGETS: TableBudget[] = [
{
tableId: 'outbound-leads',
tableName: 'Outbound Leads',
maxRows: 5000,
autoEnrich: true,
owner: '[email protected]',
monthlyCreditsEstimate: 3000,
},
{
tableId: 'event-attendees',
tableName: 'Event Attendees',
maxRows: 1000,
autoEnrich: false, // Manual trigger only
owner: '[email protected]',
monthlyCreditsEstimate: 600,
},
{
tableId: 'inbound-leads',
tableName: 'Inbound Leads',
maxRows: 2000,
autoEnrich: true,
owner: '[email protected]',
monthlyCreditsEstimate: 1200,
},
];
function auditBudgets(budgets: TableBudget[]): void {
const totalEstimate = budgets.reduce((sum, b) => sum + b.monthlyCreditsEstimate, 0);
console.log(`=== Clay Credit Budget Audit ===`);
for (const b of budgets) {
console.log(` ${b.tableName}: ${b.maxRows} rows, ~${b.monthlyCreditsEstimate} credits/mo (owner: ${b.owner})`);
}
console.log(` Total monthly estimate: ${totalEstimate} credits`);
}
Step 5: Quarterly Access Audit
## Clay Workspace Access Audit Checklist
- [ ] Review all workspace members — remove former employees
- [ ] Verify role assignments match current job functions
- [ ] Check API key usage — revoke unused keys
- [ ] Review table access — archive unused tables
- [ ] Audit credit usage by table — identify waste
- [ ] Verify provider API key connections are current
- [ ] Update API key rotation log
- [ ] Review and update table row limits
- [ ] Check webhook submission counts (approaching 50K?)
- [ ] Document any new tables or integrations added
Error Handling
| Issue | Cause | Solution |
|---|---|---|
403 on table creation | User is Viewer role | Upgrade to Member role |
| Credits exhausted mid-campaign | No budget cap on table | Set max_rows on table |
| Integration key rejected | Key was revoked | Generate new key, update integration config |
| Unauthorized data export | Viewer exported sensitive data | Review export audit log |
| Former employee still has access | No offboarding process | Immediate removal on departure |
Resources
Next Steps
For migration strategies, see clay-migration-deep-dive.
When not to use it
- →Do not use for managing personal Clay accounts
Prerequisites
Limitations
- →Clay does not have per-user credit budgets natively
- →Built-in roles have fixed permissions
How it compares
This provides a structured RBAC and audit framework for Clay workspaces, whereas standard usage lacks formal team-level governance.
Compared to similar skills
clay-enterprise-rbac side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| clay-enterprise-rbac (this skill) | 0 | 27d | No flags | Intermediate |
| flutter-development | 1,555 | 5mo | No flags | Intermediate |
| godot | 1,044 | 5mo | Review | Intermediate |
| fastapi-templates | 520 | 2mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by jeremylongshore
View all by jeremylongshore →You might also like
flutter-development
aj-geddes
Build beautiful cross-platform mobile apps with Flutter and Dart. Covers widgets, state management with Provider/BLoC, navigation, API integration, and material design.
godot
bfollington
This skill should be used when working on Godot Engine projects. It provides specialized knowledge of Godot's file formats (.gd, .tscn, .tres), architecture patterns (component-based, signal-driven, resource-based), common pitfalls, validation tools, code templates, and CLI workflows. The `godot` command is available for running the game, validating scripts, importing resources, and exporting builds. Use this skill for tasks involving Godot game development, debugging scene/resource files, implementing game systems, or creating new Godot components.
fastapi-templates
wshobson
Create production-ready FastAPI projects with async patterns, dependency injection, and comprehensive error handling. Use when building new FastAPI applications or setting up backend API projects.
software-architecture
davila7
Guide for quality focused software architecture. This skill should be used when users want to write code, design architecture, analyze code, in any case that relates to software development.
drizzle
lobehub
Drizzle ORM schema and database guide. Use when working with database schemas (src/database/schemas/*), defining tables, creating migrations, or database model code. Triggers on Drizzle schema definition, database migrations, or ORM usage questions.
frontend-design
anthropics
Create distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.