Roles & Permissions

Roles decide what each user can do inside an organization. Giving the right role keeps your work safe: builders can build, finance can watch spending, and only trusted people can change users or delete things.

Being in an organization and having a role are two separate things. Everyone in the list belongs to the organization; a role only adds extra powers on top of that.


Four roles β€” and no role at all

RoleThink of it as…Can do
OwnerThe boss of the organizationEverything, without exception.
AdminA trusted managerEverything an Owner can, apart from four things reserved for Owners β€” see below.
BuilderA makerCreate and edit agents, and use agent features they're assigned to. Cannot manage users or billing.
BillingThe finance watcherView the organization's billing and credit. A special, separate role (see below).
(no role)A regular userUse the agent features they're assigned to. Cannot build agents or manage people.

A person can hold more than one role. For example, an Owner often also holds the Billing role. A person can also hold none β€” see below.


What only an Owner can do

An Admin runs the organization day to day. Four things stay with the Owner, and all four are about who holds power or the organization's existence:

Reserved for OwnersWhy
Assign or remove the Owner roleOwnership is only handed over by an Owner. This is also why an Admin cannot promote itself.
Remove a user who is an OwnerRemoving an Owner is an ownership change by another name.
Transfer the Billing roleFinancial responsibility moves only on the Owner's say-so.
Delete the organizationThe one irreversible action.

Everything else β€” inviting people, revoking invitations, editing roles, removing users, budget groups, agents β€” an Admin can do.

An Admin can edit an Owner's other roles (adding Builder to them, say), as long as the Owner role itself is left exactly as it was.


Being in an organization without a role

Most people in an organization don't need any role. They are invited so they can chat with the agents they're given access to β€” and that is exactly what a user with no role can do.

  • They appear in the Organization Users list with a No role marker.
  • They can be added as an agent member on any of the organization's agents.
  • They can be assigned to a budget group, so their credit usage is capped like anyone else's.
  • They cannot create agents, change anyone's role, or see billing.

To create one, invite the person and simply leave every role unchecked. You can also clear all roles from an existing user β€” they stay in the organization, just without extra access.

Older organizations had a role literally called Member that did exactly this and nothing more. It has been retired because belonging to the organization already says it: someone with no role is a regular user. Nobody lost access when it was removed.


What each role can do β€” in detail

ActionOwnerAdminBuilderNo roleBilling
View the user listβœ…βœ…βœ…βœ…βœ…
Use agent features (if assigned)βœ…βœ…βœ…βœ…β€”
Create / edit agentsβœ…βœ…βœ…β€”β€”
Manage any of the org's agentsβœ…βœ…β€”β€”β€”
Invite usersβœ…βœ…*β€”β€”β€”
Revoke invitationsβœ…βœ…β€”β€”β€”
Edit user rolesβœ…βœ…**β€”β€”β€”
Remove usersβœ…βœ…***β€”β€”β€”
Create / edit budget groupsβœ…βœ…β€”β€”β€”
Assign users to a budget groupβœ…βœ…β€”β€”β€”
Assign or remove the Owner roleβœ…β€”β€”β€”β€”
Remove a user who is an Ownerβœ…β€”β€”β€”β€”
Transfer the Billing roleβœ…β€”β€”β€”β€”
Delete the organizationβœ…β€ β€”β€”β€”β€”
View organization billing / creditsβœ…β€”β€”β€”βœ…

* An Admin can invite with any role except Owner. ** Any role except Owner β€” an Admin can neither grant it nor take it away. *** Anyone except a user who holds Owner. † Only the sole Owner, and only once the organization owns no agents. If there is more than one Owner, or any agent is left, deletion is refused.

"If assigned" means a Builder or a user with no role only sees a specific agent when an Owner/Admin has given them access to it β€” see Managing Agent Access.


The Billing role is special

Most roles (Owner, Admin, Builder) are assigned to a user directly. Billing is different:

  • It is about who watches and manages credit, not who builds.
  • It is not changed from the normal "edit roles" screen. Instead it is transferred from the current holder to another user, and the recipient must accept it. Only an Owner can start or cancel that transfer.
  • There is usually one Billing holder at a time.
  • The Billing holder cannot be removed from the organization and cannot leave until the role is transferred to someone else.

See Billing & Credits for the full hand-over flow.


Which roles you can assign

The roles you may grant depend on the organization type:

Organization typeAssignable rolesNo role
CollectiveOwner, Admin, Builderβœ…
IndividualBuilderβœ…

Billing never appears here β€” it is transferred, not assigned. Owner is granted by editing an existing user's roles rather than through an invitation, and only an Owner can grant it.


Choosing the right role β€” examples

The person is…Give them…
Your co-founder who should control everythingOwner
A team lead who manages the team, agents and budgets day to dayAdmin
A developer who builds and edits agentsBuilder
A support agent who only uses an assigned agentno role β€” just invite them
Someone from finance tracking credit spendBilling (transfer it)

Where to set roles

Roles are set when you invite someone and can be edited later, both on the organization's Users tab, in the Organization Users list.

Open the Organization page, click your organization, then open the Users tab.


What happens when someone leaves

Removing a user β€” or a user leaving on their own β€” takes their access away straight away:

  • Their access to chat with the organization's agents is withdrawn.
  • Their permission to configure those agents is withdrawn.
  • Any connected-app authorizations they held for those agents are revoked.
  • A billing-role transfer still waiting for them is cancelled.

Their history stays: past conversations and credit-usage records are kept for the organization's reports. Re-inviting the person adds them back as a new organization user, not with their old access.


Next step

Put roles into practice: Users & Invitations.