Roles and Permissions in Detail
Reference: the four base roles and every additional permission explained.
This page is a complete reference: which base roles exist, what each role is allowed to do, which additional permissions you can grant individually, and how everything fits together.
If you just want to know how to assign a single permission, start with the step-by-step walkthrough in Invite Users & Assign Roles.
Overview: Base Role + Additional Permissions
Every user in a workspace has exactly one base role. It defines the framework: what the user is generally allowed to do.
On top of that, you can grant additional permissions individually - for example, to give a Viewer access to the chat, or to grant a Member full Workflow rights.
What a user can actually do - their effective permissions - is the combination of both: the base role plus any additional permissions you have assigned.
The Four Base Roles in Detail
Owner
The Owner has full control over the workspace. Every workspace has exactly one Owner - typically the person who created the workspace.
Can:
Do everything an Administrator can
Change workspace settings (name, logo, default languages, IP restrictions, billing)
Delete the workspace
Promote other users to Admin or Owner
Cannot:
Nothing is restricted. Owner permissions cannot be revoked through "Manage Permissions" either.
The Owner role can be transferred to another user, but a workspace always has exactly one Owner.
Admin
Admins handle the day-to-day management of the workspace. They have access to every feature, but cannot change the workspace's foundational settings.
Can:
View, create, edit, and delete all content (experts, sources, workflows, glossaries, groups, etc.)
Invite other users, assign roles, and remove members
Grant additional permissions to other users (only permissions the Admin themselves holds)
Manage notifications, API keys, and widgets
View analytics and usage statistics
Use the chat and search
Cannot:
Change workspace settings (only the Owner can)
Delete the workspace
Promote someone to Owner
Change or revoke an Owner's permissions
Member
Members are the active contributors in the workspace. They create and maintain content, but cannot manage users.
Can:
Create and edit experts, and add sources
Create and run workflows
Create and edit glossary terms
Create and manage groups
Use the chat and search
View notifications
Cannot:
Invite other users, change their roles, or remove them
Change workspace settings
Manage notification integrations or API keys
Administer widgets
View analytics
The Editor role is functionally identical to Member - both names map to the same permission set.
Viewer
Viewers have read-only access. They can look at content but cannot create or change anything.
Can:
View experts, workflows, glossaries, and groups
Use search
View notifications
Cannot:
Create, edit, or delete content
Use the chat by default (but this can be enabled via additional permissions)
Manage users, change settings, or configure integrations
The Viewer role is ideal for stakeholders who should stay informed but do not themselves maintain content. If you still want such people to chat with the expert, grant them the Chat Access permission individually.
At a Glance
Capability | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
View content | Yes | Yes | Yes | Yes |
Create / edit content | Yes | Yes | Yes | No |
Use chat | Yes | Yes | Yes | No* |
Use search | Yes | Yes | Yes | Yes |
Invite & manage users | Yes | Yes | No | No |
Manage workflows / glossaries | Yes | Yes | Yes | No |
Configure notifications | Yes | Yes | No | No |
Manage API keys | Yes | Yes | No | No |
View analytics | Yes | Yes | No | No |
Administer widgets | Yes | Yes | No | No |
Change workspace settings | Yes | No | No | No |
Delete the workspace | Yes | No | No | No |
*Can be enabled via additional permissions on request.
Additional Permissions by Category
Each category offers up to three levels: Administrator (full access including management), Member (create/edit), and Viewer (view only). Not every category exposes all three levels.
Chat
Permission | What it allows |
|---|---|
Chat Access | Access to the chat / agent interface. Included by default from Member upward. |
Search
Permission | What it allows |
|---|---|
Search Access | Access to the search interface. Included by default in every base role (incl. Viewer). |
Workflows
Permission | What it allows |
|---|---|
Workflow Admin | Full workflow management, including deleting others' work. |
Workflow Member | Create and run your own workflows. |
Workflow Viewer | View workflows but not modify them. |
Glossary
Permission | What it allows |
|---|---|
Glossary Admin | Full glossary management. |
Glossary Member | Create and edit glossary terms. |
Glossary Viewer | View glossaries. |
Widgets
Permission | What it allows |
|---|---|
Widget Admin | Full widget management. |
Widget Viewer | View widgets but not configure them. |
Groups
Permission | What it allows |
|---|---|
Groups Admin | Full group management. |
Groups Member | Create and manage groups. |
Groups Viewer | View groups. |
Notifications
Permission | What it allows |
|---|---|
Notifications Admin | Manage notification integrations (Email, Slack, Teams, Webhooks). |
Notifications Viewer | View notifications. |
Settings
Permission | What it allows |
|---|---|
Settings Admin | Manage workspace settings. Reserved for the Owner. |
Individual Permissions
Permission | What it allows |
|---|---|
Invite Users | Allows the user to invite other people with a base role at or below their own. |
Coming Soon
The following categories are already visible in the permissions dialog but not yet active. They will be enabled step by step:
API Keys (Admin, Member, Viewer)
Analytics (Admin, Viewer)
Tasks (Admin, Member, Viewer)
Processes (Admin, Viewer)
Until then, the default rights of the base roles apply: API keys, analytics, and processes are currently manageable or viewable by Admins and Owners.
Effective Permissions
When you scroll to the bottom of the permissions dialog, you will find the Effective Permissions section. It lists exactly which permissions the user actually holds - regardless of how they were granted.
Effective permissions combine two sources:
Inherited from Base Role - everything the selected base role grants automatically. A Member, for example, automatically receives Chat Access, Search Access, Workflow Member, Glossary Member, and so on.
Directly Selected - every permission you explicitly checked in the permissions dialog.
The sum of those two is what the user can actually do in the application.
Always use Effective Permissions to double-check after making changes. If the expected permission shows up there, your change took effect. If not, verify that you actually clicked Save Changes.
Why the Same Permission Appears Multiple Times
The permissions dialog groups rights by the base roles that include them by default. The upside: you can see at a glance which roles already include a given permission - and which do not.
The downside: some permissions appear more than once. Chat Access, for example, is included in the Owner, Admin, and Member base roles - so the option shows up three times. Search Access even shows up four times, because all four base roles include it.
The important thing: these are not different permissions. It is the same permission shown under different role contexts. A single checkmark - no matter which role it lives under - assigns the permission to the user. If in doubt, confirm the result in Effective Permissions.
Who can change permissions at all? Only Owners and Admins. Admins can only grant permissions they themselves hold, and Owner permissions can never be modified by anyone else.