Roles and access
Organization roles
Section titled “Organization roles”| Capability | Owner | Admin | Member |
|---|---|---|---|
| View members, usage, audit log | ✓ | ✓ | — (own page only) |
| Add and remove members | ✓ | ✓ (not the owner, not other admins) | — |
| Add an admin | ✓ | — | — |
| Change a member’s role | ✓ | — | — |
| Manage workspaces and their members | ✓ | ✓ | read |
| Handle join requests | ✓ | ✓ | — |
| Billing — subscription, seats, invoices | ✓ | — | — |
| General settings (name, billing email, viewer seats) | ✓ | — | — |
| View SSO configuration | ✓ | — | — |
| Transfer ownership | ✓ | — | — |
| Leave the organization | — (transfer first) | ✓ | ✓ |
There is exactly one owner. The owner cannot be removed and cannot leave; Transfer ownership (General settings) hands the role to another member who has already joined, after which the previous owner becomes a plain member.
Project access
Section titled “Project access”Access to a project is resolved in this order; the first match wins:
- Project creator → full control.
- Organization owner → full control of every organization project.
- Organization admin → edit on every organization project.
- Explicit share → Edit or View, as shared.
- Workspace member → Edit for editors, View for viewers, on projects in that workspace.
- Any member → View on organization projects that are not in any workspace.
Sharing a project explicitly still works inside an organization. Managing shares needs full control, so the owner can manage shares on any organization project.
Workspace roles
Section titled “Workspace roles”Workspaces have two roles: editor and viewer. There is no workspace owner — workspaces are managed by organization owners and admins.