Skip to main content

Roles and permissions

Roles and Permissions​

  • Admin: full control; create/rename/delete workspaces and tokens, manage members, update preferences, view audit (org + workspace). Billing changes require organization ownership. Control Center Workspace alerting (queue, eligibility, activity) is included. See Alert delivery and history.
  • Workspace Manager: manage members (except admins), create/update/delete tokens, and update preferences within assigned workspaces; view workspace audit. Control Center Workspace alerting is included.
  • Viewer: view tokens in assigned workspaces, including token and certificate Alerting and alert history (current eligibility and the alert timeline). Control Center alerting tabs require manager or admin.

Practical guidance: invite teammates or auditors as Viewer, and service owners who renew assets as Workspace Manager. The workspace creator holds the Admin role; the members API cannot grant Admin through an invitation or role change. Only the organization owner can manage billing.

Role changes are admin-only. Workspace managers can invite/remove members but cannot change admin roles.

Next steps​