Roles & Permissions
Roles decide what each user can do inside an organization. Giving the right role keeps your work safe: builders can build, finance can watch spending, and only trusted people can change users or delete things.
Being in an organization and having a role are two separate things. Everyone in the list belongs to the organization; a role only adds extra powers on top of that.
Four roles β and no role at all
| Role | Think of it as⦠| Can do |
|---|---|---|
| Owner | The boss of the organization | Everything, without exception. |
| Admin | A trusted manager | Everything an Owner can, apart from four things reserved for Owners β see below. |
| Builder | A maker | Create and edit agents, and use agent features they're assigned to. Cannot manage users or billing. |
| Billing | The finance watcher | View the organization's billing and credit. A special, separate role (see below). |
| (no role) | A regular user | Use the agent features they're assigned to. Cannot build agents or manage people. |
A person can hold more than one role. For example, an Owner often also holds the Billing role. A person can also hold none β see below.
What only an Owner can do
An Admin runs the organization day to day. Four things stay with the Owner, and all four are about who holds power or the organization's existence:
| Reserved for Owners | Why |
|---|---|
| Assign or remove the Owner role | Ownership is only handed over by an Owner. This is also why an Admin cannot promote itself. |
| Remove a user who is an Owner | Removing an Owner is an ownership change by another name. |
| Transfer the Billing role | Financial responsibility moves only on the Owner's say-so. |
| Delete the organization | The one irreversible action. |
Everything else β inviting people, revoking invitations, editing roles, removing users, budget groups, agents β an Admin can do.
An Admin can edit an Owner's other roles (adding Builder to them, say), as long as the Owner role itself is left exactly as it was.
Being in an organization without a role
Most people in an organization don't need any role. They are invited so they can chat with the agents they're given access to β and that is exactly what a user with no role can do.
- They appear in the Organization Users list with a No role marker.
- They can be added as an agent member on any of the organization's agents.
- They can be assigned to a budget group, so their credit usage is capped like anyone else's.
- They cannot create agents, change anyone's role, or see billing.
To create one, invite the person and simply leave every role unchecked. You can also clear all roles from an existing user β they stay in the organization, just without extra access.
Older organizations had a role literally called Member that did exactly this and nothing more. It has been retired because belonging to the organization already says it: someone with no role is a regular user. Nobody lost access when it was removed.
What each role can do β in detail
| Action | Owner | Admin | Builder | No role | Billing |
|---|---|---|---|---|---|
| View the user list | β | β | β | β | β |
| Use agent features (if assigned) | β | β | β | β | β |
| Create / edit agents | β | β | β | β | β |
| Manage any of the org's agents | β | β | β | β | β |
| Invite users | β | β * | β | β | β |
| Revoke invitations | β | β | β | β | β |
| Edit user roles | β | β ** | β | β | β |
| Remove users | β | β *** | β | β | β |
| Create / edit budget groups | β | β | β | β | β |
| Assign users to a budget group | β | β | β | β | β |
| Assign or remove the Owner role | β | β | β | β | β |
| Remove a user who is an Owner | β | β | β | β | β |
| Transfer the Billing role | β | β | β | β | β |
| Delete the organization | β β | β | β | β | β |
| View organization billing / credits | β | β | β | β | β |
* An Admin can invite with any role except Owner. ** Any role except Owner β an Admin can neither grant it nor take it away. *** Anyone except a user who holds Owner. β Only the sole Owner, and only once the organization owns no agents. If there is more than one Owner, or any agent is left, deletion is refused.
"If assigned" means a Builder or a user with no role only sees a specific agent when an Owner/Admin has given them access to it β see Managing Agent Access.
The Billing role is special
Most roles (Owner, Admin, Builder) are assigned to a user directly. Billing is different:
- It is about who watches and manages credit, not who builds.
- It is not changed from the normal "edit roles" screen. Instead it is transferred from the current holder to another user, and the recipient must accept it. Only an Owner can start or cancel that transfer.
- There is usually one Billing holder at a time.
- The Billing holder cannot be removed from the organization and cannot leave until the role is transferred to someone else.
See Billing & Credits for the full hand-over flow.
Which roles you can assign
The roles you may grant depend on the organization type:
| Organization type | Assignable roles | No role |
|---|---|---|
| Collective | Owner, Admin, Builder | β |
| Individual | Builder | β |
Billing never appears here β it is transferred, not assigned. Owner is granted by editing an existing user's roles rather than through an invitation, and only an Owner can grant it.
Choosing the right role β examples
| The person is⦠| Give them⦠|
|---|---|
| Your co-founder who should control everything | Owner |
| A team lead who manages the team, agents and budgets day to day | Admin |
| A developer who builds and edits agents | Builder |
| A support agent who only uses an assigned agent | no role β just invite them |
| Someone from finance tracking credit spend | Billing (transfer it) |
Where to set roles
Roles are set when you invite someone and can be edited later, both on the organization's Users tab, in the Organization Users list.
Open the Organization page, click your organization, then open the Users tab.
What happens when someone leaves
Removing a user β or a user leaving on their own β takes their access away straight away:
- Their access to chat with the organization's agents is withdrawn.
- Their permission to configure those agents is withdrawn.
- Any connected-app authorizations they held for those agents are revoked.
- A billing-role transfer still waiting for them is cancelled.
Their history stays: past conversations and credit-usage records are kept for the organization's reports. Re-inviting the person adds them back as a new organization user, not with their old access.
Next step
Put roles into practice: Users & Invitations.