Skip to navigation

Roles and permissions

What owners, admins and members can do

Every member of an organization holds one of three roles. A person’s role is per organization: the same person can be an owner of one and a member of another.

OwnerAdminMember
See the organization and its members✓✓✓
Create API keys and OAuth clients✓✓✓
See, rotate and revoke credentials they created✓✓✓
See, rotate and revoke anyone’s credentials✓✓
Rename the organization✓✓
Invite people, and cancel invitations✓✓
Suspend or remove members✓✓
See billing, prices and usage history✓✓
Assign and revoke Chart Review seats✓✓
Buy credit and Chart Review seats✓
Change a member’s role✓
Claim and verify email domains✓
Accept the terms of service for the organization✓

A few of these are split deliberately:

  • An admin can assign Chart Review seats but cannot buy more. Deciding which colleague gets a licence and spending the organization’s money are different decisions.
  • Only an owner accepts the terms of service, because accepting binds the company. Every member can see when acceptance is outstanding.
  • Members can create credentials, because developers need keys to work. A member sees and manages only the credentials they created; owners and admins see all of them.

A Chart Review seat is separate from a role. An owner may hold no seat, and a member may hold one. See Chart Review seats.