Roles

What each workspace role may do through the dashboard API.

dev · https://api.dev.oprag.ai

Roles apply to dashboard (JWT) requests. Key-authenticated requests are not made by a person and carry no role — an integration key's reach is bounded by its project, not by a role.

RoleCan
OwnerEverything an admin can, plus billing and workspace deletion. One per workspace.
AdminManage projects, documents, keys, members, integrations, and channels. Most endpoints marked admin require this.
MemberRead projects and conversations, run test prompts. Cannot issue keys or change settings.

Some endpoints additionally require a plan, shown as Growth+. That is a billing check, not a role check, and also returns 403.

Ready to ship?

Get started free