# Managing Pools

Pools in the Zuplo AI Gateway grant users access to apps. Pools are
hierarchical, so access propagates to sub-pools only when the user also has
permission to view the Zuplo project that contains the AI Gateway. Pool or
sub-pool membership doesn't grant Zuplo project access. Pools are also where you
define usage limits and [policy templates](./policy-templates.mdx).

## Creating a Pool

Creating a pool requires Admin rights on the Zuplo project or Zuplo account for
a top-level pool, or on the parent pool for a sub-pool. As a convenience, the
Portal disables the **New Pool** button when you don't have the required rights.

<Stepper>

1. Open the [Apps](https://portal.zuplo.com/+/account/project/ai/pools) tab of
   your AI Gateway project in the Zuplo Portal.

1. Click **New Pool** above the tree.

1. Choose where the pool sits. Once the gateway has at least one pool, the
   dialog shows a parent picker above the name field; leave it on **No parent
   pool** for a top-level pool, or pick a pool to create a sub-pool under it.

1. Enter the name of your pool.

1. Click **Create Pool**

</Stepper>

You can also create a sub-pool from the parent itself: select it in the tree and
click **Create Sub-Pool** in the pool's header.

After creating a pool, use its tabs to configure it:

- **Policy Template**—the pool's [policy template](./policy-templates.mdx), the
  starting policy chain for apps created in the pool.
- **Usage & Limits**—shared budgets for the pool, its sub-pools, and their apps.
  See [Usage Limits](./usage-limits.mdx).
- **Members**—who belongs to the pool.

## Adding Pool Members

Pool members are the users who belong to a pool and can access its apps,
provided they also have permission to view the Zuplo project. AI provider access
is separate and depends on the user's Zuplo account or Zuplo project role.

<Stepper>

1. Open the [Apps](https://portal.zuplo.com/+/account/project/ai/pools) tab of
   your AI Gateway project in the Zuplo Portal.

1. Select the pool you want to add members to.

1. Click the **Members** tab.

1. Click **Add member**.

1. Type the email address of the user you want to add. If the user is already a
   member of your Zuplo account, they are added directly to the pool. Otherwise,
   they are invited to join the Zuplo account and then added to the pool.

1. Select the role for the user:
   - **Member**: Can access apps owned by the pool.
   - **Admin**: Can manage the pool's settings, members, and apps.

     :::caution{title="The Member role requires RBAC"}

     Role-based access control (RBAC) is an optional enterprise add-on on your
     Zuplo account. Without it, every invited user is an **Admin**. For more
     information see the
     [document on roles and permissions](../articles/accounts/roles-and-permissions.mdx).

     :::

1. Click **Add member** to confirm.

1. The user will receive an email notification if they're being invited to the
   Zuplo account.

</Stepper>
