---
title: "Roles & permissions"
description: "Access works on two levels. Your organization role sets what you can do across the whole account — billing, members, and workspaces. Your workspace role sets what you can do ins…"
url: "https://sotaagents.ai/manual/admin-console/roles-and-permissions"
generated_by: "sotaagents-ldp"
docs_index: "https://sotaagents.ai/manual/llms.txt"
locale: "en"
---

# Roles & permissions

Access works on two levels. Your **organization role** sets what you can do across the whole account — billing, members, and workspaces. Your **workspace role** sets what you can do inside a specific workspace. A person can hold different roles in different workspaces, and org owners and admins automatically get admin rights in every workspace under the org.

![The organization members table listing each member with their organization role and status](/manual/assets/product/console-participants-20260813.webp)
_Members lists everyone in the organization and the role they hold._

### Organization roles

| Role | What they can do |
| --- | --- |
| Owner | Manage organization membership, workspaces, API keys, apps, security and the owner/admin credit-policy actions described below. Ownership does not grant platform subscription or money-movement authority. |
| Admin | Manage organization membership, workspaces, apps and many credit-policy settings. Exact screens and mutations are still enforced by the API; “Admin” is not shorthand for unrestricted billing. |
| Member | Use the workspaces they've been added to. |

### Subscription and credit authority

| Action | Authority |
| --- | --- |
| Read organization credit overview | Organization members |
| Credit package CRUD/assignment and rolling user limit | Organization Owner or Admin |
| Read Guest Credit add-on and manage workspace guest allocations | Organization Owner or Admin |
| Upgrade, downgrade, cancel plan; top-up or refund | SotaAgents operations team only |
| Pool/seat configuration and Guest Credit add-on lifecycle | SotaAgents operations team only |

### Workspace roles

![The workspace participants tab listing members with their workspace role](/manual/assets/product/ws-participants-20260813.webp)
_Workspace roles are set separately, on the workspace itself._

| Role | What they can do |
| --- | --- |
| Workspace Admin (`WS_ADMIN`) | Manage workspace settings, members, apps, integrations, guardrails, and MCP servers. |
| Workspace Member (`WS_MEMBER`) | Use the workspace and the capabilities available there. Cannot change membership, apps, or workspace settings. Legacy Editor/Chatter values are compatibility-mapped to this role. |

> [!NOTE]
> Org owners and admins are auto-promoted
>
> If you're an org owner or admin, you have workspace-admin power in every workspace under your org — no need to invite yourself separately.
