Roles & Permissions
Role-based access control for your organization.
Advanced RBAC features require a Business plan or higher.
Organization Roles
Owner
Full control over the organization:
- All admin permissions
- Manage billing and subscription
- Delete organization
- Transfer ownership
Only one owner per organization.
Admin
Manage organization settings and members:
- Invite and remove members
- Manage teams
- Configure security settings
- View audit logs
- Access analytics
Cannot:
- Delete organization
- Manage billing
Member
Standard organization access:
- Create and manage own documents
- Share documents with organization
- Join teams
- Use all features per plan
Viewer
Read-only access:
- View shared documents
- Add comments (if enabled)
- Cannot edit or create documents
Resource Permissions
Documents
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View | ✓ | ✓ | ✓ | ✓ |
| Edit | ✓ | ✓ | ✓ | - |
| Delete | ✓ | ✓ | Own | - |
| Share | ✓ | ✓ | ✓ | - |
Teams
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| Create | ✓ | ✓ | - | - |
| Manage | ✓ | ✓ | Own | - |
| Delete | ✓ | ✓ | - | - |
| Join | ✓ | ✓ | ✓ | ✓ |
Organization Settings
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View settings | ✓ | ✓ | - | - |
| Edit settings | ✓ | ✓ | - | - |
| Billing | ✓ | - | - | - |
| Delete org | ✓ | - | - | - |
Changing Roles
Promote/Demote Members
- Go to Organization → Members
- Find the member
- Click role dropdown
- Select new role
- Confirm change
Role changes take effect immediately. The user may need to refresh their session.
Transfer Ownership
- Go to Organization → Settings
- Click Transfer Ownership
- Select new owner
- Confirm transfer
- You become an Admin
Feature-Based Permissions
Some features have plan-based access:
| Feature | Free | Pro | Business | Enterprise |
|---|---|---|---|---|
| SAML SSO | - | - | ✓ | ✓ |
| SCIM | - | - | - | ✓ |
| BYOB | - | - | - | ✓ |
| API Access | - | - | ✓ | ✓ |
Best Practices
- Limit number of owners (ideally 1-2)
- Use Admin role sparingly
- Assign Member for most users
- Use Viewer for external collaborators
- Review permissions regularly
Next Steps
- Members - Manage organization members
- SAML SSO - Configure single sign-on
- SCIM Provisioning - Automate user provisioning
- Authentication - Authentication options
Last updated on