Understanding Update Project ACLs

Last updated: February 13, 2026

Summary

Goal: Understand which project actions require the update permission in Braintrust.

Features: Project-level access control (ACL), permission management, retention policies.

Applicable To

Plans: Any

Deployments: Any

What Update Permission Allows

Project-Level Resources

  • Project: Edit name and description

  • Project scores: Create, update, delete human review scores (not automated evaluation scores)

  • Project tags: Create, update, delete

  • Span iframes: Create, update, delete

  • MCP servers: Create, update, delete

  • Project automations: Create, update, delete retention policies and other automations

Project Resources

  • Experiments: Modify metadata and experiment data

  • Datasets: Modify dataset metadata and rows

  • Logs: Modify logs in the project

What Update Permission Does Not Include

  • Delete: Deleting projects or resources requires separate Delete permission

  • Manage access: Changing access permissions requires separate Manage access permission

  • Create: Creating new experiments, datasets, or logs requires separate Create permission