Permissions
Goal: Control what team members can do.
Role Definitions
| Role | Create | Edit | Delete | Invite | Manage |
|---|---|---|---|---|---|
| Viewer | ✗ | ✗ | ✗ | ✗ | ✗ |
| Editor | ✓ | ✓ | ✗ | ✗ | ✗ |
| Admin | ✓ | ✓ | ✓ | ✓ | ✓ |
What Each Role Can Do
Viewer
- View workspace and surfaces
- Run existing warm queries
- See API responses
- Cannot modify anything
Editor
- Everything Viewer can do
- Create connections, surfaces, warm queries
- Edit existing resources
- Propose changes (requires approval)
Admin
- Everything Editor can do
- Delete resources
- Invite and remove team members
- Change roles
- Manage workspace settings
Changing Roles
- Go to Team tab
- Find the user
- Click their current role
- Select new role
- Confirm
Role Change Audit
Every role change is logged:
{
"action": "role_change",
"user": "sarah@company.com",
"oldRole": "Editor",
"newRole": "Admin",
"changedBy": "mike@company.com",
"timestamp": "2026-01-18T10:30:00Z"
}
Best Practices
| Practice | Why |
|---|---|
| Minimum necessary access | Reduce risk |
| Few Admins | Limit who can delete |
| Use Viewers for external partners | Read-only access |
| Review roles periodically | Remove stale access |
Governance applies to team management too. Every permission change is logged and attributable.
Next Steps
| If you want to... | Go to... |
|---|---|
| Deep dive on access model | User Management → |
| Manage API keys | Security → |