Users and access
Roles and permissions
Four roles, and what each can do.
Everyone in an organization has exactly one role.
| Role | Can do |
|---|---|
| Viewer | Read what they are allowed to see. Create their own API keys. Save memories. |
| Member | Everything a viewer can, plus create content and their own connectors. |
| Org admin | Everything a member can, plus manage people, settings and shared connectors. |
| Super admin | Everything, across every organization. For whoever operates the instance. |
The thing that surprises people
Roles do not grant visibility into content.
An org admin can manage connectors, invite people and change settings — and still cannot read another person's private content. Administration and readership are separate on purpose, so running the system does not require being able to read everything in it.
If you need to see specific content, it has to be shared with you through an access profile, regardless of your role.
Changing someone's role
Settings → Members → change role. Effective immediately, including for any API keys they created — a key can never do more than its creator can do today.
Which role to give
- Viewer — most people. Enough to use LensHub through an agent.
- Member — people who will add their own connectors or content.
- Org admin — the two or three people who run it.
- Super admin — whoever operates the instance itself. Usually one person.
Full permission list in the reference, generated from the running code.