Documentation
Open app

Roles & permissions

On this page

Access works on two levels. Your organization role sets what you can do across the whole account — billing, members, and workspaces. Your workspace role sets what you can do inside a specific workspace. A person can hold different roles in different workspaces, and org owners and admins automatically get admin rights in every workspace under the org.

The organization members table listing each member with their organization role and status
Members lists everyone in the organization and the role they hold.

Organization roles#

RoleWhat they can do
OwnerManage organization membership, workspaces, API keys, apps, security and the owner/admin credit-policy actions described below. Ownership does not grant platform subscription or money-movement authority.
AdminManage organization membership, workspaces, apps and many credit-policy settings. Exact screens and mutations are still enforced by the API; “Admin” is not shorthand for unrestricted billing.
MemberUse the workspaces they've been added to.

Subscription and credit authority#

ActionAuthority
Read organization credit overviewOrganization members
Credit package CRUD/assignment and rolling user limitOrganization Owner or Admin
Read Guest Credit add-on and manage workspace guest allocationsOrganization Owner or Admin
Upgrade, downgrade, cancel plan; top-up or refundSotaAgents operations team only
Pool/seat configuration and Guest Credit add-on lifecycleSotaAgents operations team only

Workspace roles#

The workspace participants tab listing members with their workspace role
Workspace roles are set separately, on the workspace itself.
RoleWhat they can do
Workspace Admin (WS_ADMIN)Manage workspace settings, members, apps, integrations, guardrails, and MCP servers.
Workspace Member (WS_MEMBER)Use the workspace and the capabilities available there. Cannot change membership, apps, or workspace settings. Legacy Editor/Chatter values are compatibility-mapped to this role.
Org owners and admins are auto-promoted

If you're an org owner or admin, you have workspace-admin power in every workspace under your org — no need to invite yourself separately.

Contents

Esc

Search titles and body text across every chapter.