Roles and Permissions in Detail

Reference: the four base roles and every additional permission explained.

This page is a complete reference: which base roles exist, what each role is allowed to do, which additional permissions you can grant individually, and how everything fits together.

If you just want to know how to assign a single permission, start with the step-by-step walkthrough in Invite Users & Assign Roles.

Overview: Base Role + Additional Permissions

Every user in a workspace has exactly one base role. It defines the framework: what the user is generally allowed to do.

On top of that, you can grant additional permissions individually - for example, to give a Viewer access to the chat, or to grant a Member full Workflow rights.

What a user can actually do - their effective permissions - is the combination of both: the base role plus any additional permissions you have assigned.

The Four Base Roles in Detail

Owner

The Owner has full control over the workspace. Every workspace has exactly one Owner - typically the person who created the workspace.

Can:

  • Do everything an Administrator can

  • Change workspace settings (name, logo, default languages, IP restrictions, billing)

  • Delete the workspace

  • Promote other users to Admin or Owner

Cannot:

  • Nothing is restricted. Owner permissions cannot be revoked through "Manage Permissions" either.

â„č

The Owner role can be transferred to another user, but a workspace always has exactly one Owner.

Admin

Admins handle the day-to-day management of the workspace. They have access to every feature, but cannot change the workspace's foundational settings.

Can:

  • View, create, edit, and delete all content (experts, sources, workflows, glossaries, groups, etc.)

  • Invite other users, assign roles, and remove members

  • Grant additional permissions to other users (only permissions the Admin themselves holds)

  • Manage notifications, API keys, and widgets

  • View analytics and usage statistics

  • Use the chat and search

Cannot:

  • Change workspace settings (only the Owner can)

  • Delete the workspace

  • Promote someone to Owner

  • Change or revoke an Owner's permissions

Member

Members are the active contributors in the workspace. They create and maintain content, but cannot manage users.

Can:

  • Create and edit experts, and add sources

  • Create and run workflows

  • Create and edit glossary terms

  • Create and manage groups

  • Use the chat and search

  • View notifications

Cannot:

  • Invite other users, change their roles, or remove them

  • Change workspace settings

  • Manage notification integrations or API keys

  • Administer widgets

  • View analytics

â„č

The Editor role is functionally identical to Member - both names map to the same permission set.

Viewer

Viewers have read-only access. They can look at content but cannot create or change anything.

Can:

  • View experts, workflows, glossaries, and groups

  • Use search

  • View notifications

Cannot:

  • Create, edit, or delete content

  • Use the chat by default (but this can be enabled via additional permissions)

  • Manage users, change settings, or configure integrations

💡

The Viewer role is ideal for stakeholders who should stay informed but do not themselves maintain content. If you still want such people to chat with the expert, grant them the Chat Access permission individually.

At a Glance

Capability

Owner

Admin

Member

Viewer

View content

Yes

Yes

Yes

Yes

Create / edit content

Yes

Yes

Yes

No

Use chat

Yes

Yes

Yes

No*

Use search

Yes

Yes

Yes

Yes

Invite & manage users

Yes

Yes

No

No

Manage workflows / glossaries

Yes

Yes

Yes

No

Configure notifications

Yes

Yes

No

No

Manage API keys

Yes

Yes

No

No

View analytics

Yes

Yes

No

No

Administer widgets

Yes

Yes

No

No

Change workspace settings

Yes

No

No

No

Delete the workspace

Yes

No

No

No

*Can be enabled via additional permissions on request.

Additional Permissions by Category

Each category offers up to three levels: Administrator (full access including management), Member (create/edit), and Viewer (view only). Not every category exposes all three levels.

Chat

Permission

What it allows

Chat Access

Access to the chat / agent interface. Included by default from Member upward.

Permission

What it allows

Search Access

Access to the search interface. Included by default in every base role (incl. Viewer).

Workflows

Permission

What it allows

Workflow Admin

Full workflow management, including deleting others' work.

Workflow Member

Create and run your own workflows.

Workflow Viewer

View workflows but not modify them.

Glossary

Permission

What it allows

Glossary Admin

Full glossary management.

Glossary Member

Create and edit glossary terms.

Glossary Viewer

View glossaries.

Widgets

Permission

What it allows

Widget Admin

Full widget management.

Widget Viewer

View widgets but not configure them.

Groups

Permission

What it allows

Groups Admin

Full group management.

Groups Member

Create and manage groups.

Groups Viewer

View groups.

Notifications

Permission

What it allows

Notifications Admin

Manage notification integrations (Email, Slack, Teams, Webhooks).

Notifications Viewer

View notifications.

Settings

Permission

What it allows

Settings Admin

Manage workspace settings. Reserved for the Owner.

Individual Permissions

Permission

What it allows

Invite Users

Allows the user to invite other people with a base role at or below their own.

Coming Soon

The following categories are already visible in the permissions dialog but not yet active. They will be enabled step by step:

  • API Keys (Admin, Member, Viewer)

  • Analytics (Admin, Viewer)

  • Tasks (Admin, Member, Viewer)

  • Processes (Admin, Viewer)

Until then, the default rights of the base roles apply: API keys, analytics, and processes are currently manageable or viewable by Admins and Owners.

Effective Permissions

When you scroll to the bottom of the permissions dialog, you will find the Effective Permissions section. It lists exactly which permissions the user actually holds - regardless of how they were granted.

Effective permissions combine two sources:

  1. Inherited from Base Role - everything the selected base role grants automatically. A Member, for example, automatically receives Chat Access, Search Access, Workflow Member, Glossary Member, and so on.

  2. Directly Selected - every permission you explicitly checked in the permissions dialog.

The sum of those two is what the user can actually do in the application.

💡

Always use Effective Permissions to double-check after making changes. If the expected permission shows up there, your change took effect. If not, verify that you actually clicked Save Changes.

Why the Same Permission Appears Multiple Times

The permissions dialog groups rights by the base roles that include them by default. The upside: you can see at a glance which roles already include a given permission - and which do not.

The downside: some permissions appear more than once. Chat Access, for example, is included in the Owner, Admin, and Member base roles - so the option shows up three times. Search Access even shows up four times, because all four base roles include it.

The important thing: these are not different permissions. It is the same permission shown under different role contexts. A single checkmark - no matter which role it lives under - assigns the permission to the user. If in doubt, confirm the result in Effective Permissions.

â„č

Who can change permissions at all? Only Owners and Admins. Admins can only grant permissions they themselves hold, and Owner permissions can never be modified by anyone else.