Reference
Roles and permissions
Exactly what each role can do.
Roles are additive — each includes everything the one before it can do. See Roles for what this means in practice.
| Permission | Viewer | Member | Org admin | Super admin |
|---|---|---|---|---|
apikey:create_admin | ✓ | ✓ | ||
apikey:create_read | ✓ | ✓ | ✓ | ✓ |
apikey:create_write | ✓ | ✓ | ✓ | |
apikey:manage_own | ✓ | ✓ | ✓ | ✓ |
connector:create_personal | ✓ | ✓ | ✓ | |
connector:manage_global | ✓ | ✓ | ||
connector:manage_own | ✓ | ✓ | ✓ | |
connector:promote_global | ✓ | ✓ | ||
connector:read_visible | ✓ | ✓ | ✓ | ✓ |
context:delete | ✓ | ✓ | ✓ | |
context:read | ✓ | ✓ | ✓ | ✓ |
context:read_private_own | ✓ | ✓ | ✓ | ✓ |
context:write | ✓ | ✓ | ✓ | |
instance:manage_orgs | ✓ | |||
memory:read | ✓ | ✓ | ✓ | ✓ |
memory:write | ✓ | ✓ | ✓ | ✓ |
org:manage_members | ✓ | ✓ | ||
settings:manage | ✓ | ✓ | ||
sshkeys:manage | ||||
stats:view_org_aggregate | ✓ | ✓ | ||
stats:view_visible | ✓ | ✓ | ✓ | ✓ |
Reading another person's private content is absent from every column, at every role. That is not an omission — no role grants it. Visibility comes from ownership and access profiles, never from a role.