Roles
What each workspace role may do through the dashboard API.
Roles apply to dashboard (JWT) requests. Key-authenticated requests are not made by a person and carry no role — an integration key's reach is bounded by its project, not by a role.
| Role | Can |
|---|---|
| Owner | Everything an admin can, plus billing and workspace deletion. One per workspace. |
| Admin | Manage projects, documents, keys, members, integrations, and channels. Most endpoints marked admin require this. |
| Member | Read projects and conversations, run test prompts. Cannot issue keys or change settings. |
Some endpoints additionally require a plan, shown as Growth+. That is a billing check, not a role check, and also returns 403.
Ready to ship?
Get started free