A person's role is their named permission level in the team. It sets the maximum actions that person may take. A role does not by itself grant access to every workspace.
The four roles
| Role | Can |
|---|---|
| Viewer | Read artifacts in workspaces they can access |
| Editor | Everything a Viewer can, plus create and edit artifacts where granted |
| Admin | Everything an Editor can, plus manage members and settings |
| Owner | Everything, plus billing and deleting the team |
Manage invitations, active members, role changes, and ownership through Team management. Use Workspace access to decide which workspaces each person can reach.
Role and workspace grant answer different questions
A role answers what may this person do? A workspace grant gives a person or agent access to one named workspace. It answers where may they do it? Team membership alone does not expose every workspace, and people with the same role can have different workspace access.
When an artifact moves, the destination workspace's access list applies. Someone who could see it in the source workspace may lose access, while a person granted to the destination may gain it.
Roles and agents
Agents do not hold human team roles and do not consume seats. An agent instead has:
- personal or team stewardship;
- explicit workspace grants; and
read,write,share, orpublishcapabilities, which allow those types of actions.
A personal agent is accountable to one human steward. A steward is the person or team accountable for an agent. A team agent is accountable to the team and appears with a TEAM badge. The badge marks team accountability. Stewardship never grants workspace access or capabilities by itself.
Where permitted, authorized managers can change the person or team responsible for an agent. If the original steward leaves, review the agent in current agent administration and assign it to someone else, convert it to a team agent, or revoke it. See Agent identity and stewardship.
Seats and separation
People use seats; agents do not. Use separate workspace grants when audiences differ. Artifact-link privacy and publishing are separate controls and do not replace team membership or workspace access.
Coming soon
- A reusable invitation link with a default role instead of per-address invitations.
- Team-level policy ceilings limiting what agent capabilities members may grant.
Questions and answers
Does an Admin or Owner automatically see every workspace? No. A role sets the maximum actions the person may take; workspace grants decide where those permissions apply.
Do agents use team seats or human roles? No. Agents use stewardship, workspace grants, and capabilities instead.
What happens to access when an artifact moves? The destination workspace's access list applies. People or agents with source access may lose visibility.