Organization roles control administration. An artifact's visibility controls who can read its content.
To check the active organization and your current role, open Settings → Profile. The page shows the organization's name and your role.
Roles
- Owner – manages billing, roles, member invitations and removal, single sign-on, additional email domains, organization name and slug, logo, and API keys.
- Admin – manages billing, Member invitations and removal, organization name and slug, logo, API keys, and public or company artifacts. Admins cannot change roles, configure single sign-on or email domains, or remove Admins and Owners.
- Member – publishes artifacts, updates and shares public or company artifacts, manages private artifacts they created, and manages their own user API keys. Member-owned keys cannot receive administrative scope.
An organization can have more than one Owner. Every Owner has the same authority; there is no primary Owner. The final Owner cannot be demoted or removed until another member is promoted to Owner.
Keep Owner and Admin roles limited to people who should administer the organization. Use separate organizations when you need separate administrative boundaries.
Only Owners can add, verify, transfer, or remove company email domains. A domain transfer also requires final confirmation from a current target Owner in the dashboard. See Company email domains.
Content access stays separate
An administrative role does not grant access to private artifact content. A private artifact can be read only by its creator and invited people.
Offboarding and recovery
Owners can manage a private artifact's access and lifecycle when offboarding a member or recovering organization content. That exceptional authority does not let an Owner read or export the content unless the Owner created the artifact or was invited.
Admins can help manage public and company artifacts during normal operations. Private artifact offboarding requires an Owner.