Workspaces
Roles & access
The four workspace roles and what each one can do.
Every member has exactly one role per workspace. Roles are enforced on the server for every action, not just hidden in the UI.
The four roles
| Role | Can do |
|---|---|
| Owner | Everything, including billing, subscription, and deleting the workspace. |
| Admin | Manage members, groups, projects, environments, and settings. Cannot delete the workspace. |
| Member | Create and run work; limited access to settings. |
| Viewer | Read-only access to permitted areas. |
Changing roles
Owners and admins change roles from Members. A change takes effect on the member's next action, and the change is recorded in the audit log.
Least privilege
Give people the lowest role that still lets them do their job. Use groups to keep this consistent as teams grow.
Related
Last updated 2026-09-02