Members & Roles
Built-in roles, custom roles, and inviting people to your organization.
Studio → Settings → Members & Roles manages who's in your organization and what they're allowed to do. Every member has exactly one role at a time — a built-in role, or a custom one your organization has defined.
Built-in roles
| Role | What it can do |
|---|---|
Owner | Full access to everything. Cannot be removed from the organization. |
Admin | Full access to everything except end-user-level usage detail. |
Editor | Can create and manage AI resources (Agents, Teams, Workflows, Knowledge Bases, etc.); read-only on organization settings. |
Normal | Read and execute access to AI resources — can run things, can't create or configure them. |
These four are fixed, code-defined permission sets — not editable, and always available.
Custom roles
Beyond the four built-ins, an Admin or Owner can define custom roles with a specific subset of permissions (Studio → Settings → Members & Roles → Roles tab), for when none of the built-ins fit — someone who should manage Budgets but nothing else, for example.
Inviting members
Invite by email; the invite carries the role they'll have on acceptance. An invitation can be revoked before it's accepted. Once someone's a member, their role can be changed at any time from their row in the Members table.
Permission changes take effect immediately
There's no cache delay on role/permission changes the way there is on API key revocation — a member's new role applies to their very next request.