Permissions
What each base role can do, resource by resource.
Legend
Allowed everywhere in scope
Allowed within their own team only
Not allowed
| Action | Member | Editor | Manager | Admin | Owner |
|---|---|---|---|---|---|
| Users — Accounts, profiles, and their lifecycle | |||||
| View | Not allowed | Allowed within own team | Allowed | Allowed | Allowed |
| Invite | Not allowed | Not allowed | Allowed | Allowed | Allowed |
| Edit | Not allowed | Not allowed | Allowed within own team | Allowed | Allowed |
| Suspend | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Delete | Not allowed | Not allowed | Not allowed | Allowed within own team | Allowed |
| Roles & permissions — Who can change what anyone else can do | |||||
| View | Not allowed | Not allowed | Allowed | Allowed | Allowed |
| Assign | Not allowed | Not allowed | Allowed within own team | Allowed | Allowed |
| Create | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Delete | Not allowed | Not allowed | Not allowed | Not allowed | Allowed |
| Teams & groups — Organisational structure and membership | |||||
| View | Allowed within own team | Allowed | Allowed | Allowed | Allowed |
| Create | Not allowed | Not allowed | Allowed within own team | Allowed | Allowed |
| Edit | Not allowed | Allowed within own team | Allowed | Allowed | Allowed |
| Delete | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Content — Documents, drafts, and shared workspaces | |||||
| View | Allowed within own team | Allowed | Allowed | Allowed | Allowed |
| Create | Allowed within own team | Allowed | Allowed | Allowed | Allowed |
| Edit | Not allowed | Allowed | Allowed | Allowed | Allowed |
| Delete | Not allowed | Allowed within own team | Allowed | Allowed | Allowed |
| Billing — Plans, payment methods, and invoices | |||||
| View | Not allowed | Not allowed | Allowed within own team | Allowed | Allowed |
| Edit | Not allowed | Not allowed | Not allowed | Allowed within own team | Allowed |
| Export | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Audit & reports — Monitoring and compliance evidence | |||||
| View | Not allowed | Not allowed | Allowed within own team | Allowed | Allowed |
| Export | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Integrations & API — Connected apps, keys, and webhooks | |||||
| View | Not allowed | Allowed within own team | Allowed | Allowed | Allowed |
| Connect | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Rotate keys | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Workspace settings — Security policy, SSO, and domains | |||||
| View | Not allowed | Not allowed | Not allowed | Allowed | Allowed |
| Edit | Not allowed | Not allowed | Not allowed | Allowed within own team | Allowed |
| Delete workspace | Not allowed | Not allowed | Not allowed | Not allowed | Allowed |
How permissions resolve
- 1The account's base role sets the floor. Every account has exactly one.
- 2Group membership can only add permissions, never remove them.
- 3Admin grants layer on top and carry their own scope and expiry.
- 4An explicit deny at any level wins over every grant below it.
- 5Disabled modules hide their permissions entirely, regardless of role.
Check an account
See the permissions a specific person actually holds once role, groups, and admin grants are combined.
Open effective permissions