Skip to content

Roles & permissions

Every member of an organization has exactly one role in that organization. Roles are per-organization - the same person can be an Admin in one organization and a Viewer in another.

From highest to lowest:

Owner > Admin > Member > Auditor > Viewer

RoleWhat it grants
OwnerFull control - invite/remove members, change roles, manage billing, delete the organization. There must always be at least one Owner.
AdminDelegated management - invite members, manage instances and resources, most of what an Owner can do - but cannot delete the organization.
MemberStandard working access - use and manage the organization’s instances and shared resources. Cannot invite members or change organization-wide settings.
AuditorRead-oriented access, scoped toward audit and compliance visibility. Sits below Member, above Viewer - not an elevated role, and not a synonym for “compliance admin”.
ViewerRead-only access to the organization’s resources.

Auditor is easy to misread as a step up because of what it’s for (oversight), but its actual position in the hierarchy is between Member and Viewer. Don’t grant it expecting Admin-like reach.

The Auditor role is a full option in both the Invite member dialog and the member role dropdown on an organization’s Members tab - you don’t need to go through your account team to assign it.

If they need to…Give them
Own billing, delete the org, have no restrictionsOwner
Manage members, instances, and settings day to dayAdmin
Do their own work - provision, configure, deployMember
Review activity and compliance evidence, nothing moreAuditor
Just look around - dashboards, reports, nothing they can changeViewer

When in doubt, start narrower (Member or Viewer) and raise the role later rather than starting with Admin. Every role change is recorded in the organization’s audit trail either way.

On top of the role hierarchy, an organization can further restrict what a specific member can touch within their role, resource by resource. Five resource areas can be individually set to no access, read-only, or full access: billing, AI features, cloud instances, the audit log, and fleet management. A handful of named presets cover common cases - for example, a “billing manager” preset grants full billing access with read-only visibility into AI usage and instances, and no audit-log or fleet access at all - or you can customize each area individually.

This is an additional restriction layered on top of a member’s role, not a way to grant more than their role already allows. A Viewer given “full access” to billing still can’t do anything a Viewer’s role otherwise forbids elsewhere; the override can only take away access within what the role already grants, never add capability the role itself doesn’t have. A member with no override configured for them is unrestricted within their role, exactly as if this feature didn’t exist for them.

Separately from any organization’s own roles, Sencai staff can hold platform-level administrative access that spans across organizations - used for support and platform operations, not something any customer role grants. It’s entirely independent of your organization’s own Owner/Admin roles and isn’t something you can grant to a teammate.