Understanding roles & permissions

v1 (current)

What owners, admins, and members can each do.

Every organization member has exactly one role: Owner, Admin, or Member.

Owner

Full control: organization settings, billing, feature flags, and can change or remove any member, including other admins.

Admin

Can invite and remove members, update organization settings, and view organization-wide activity. Cannot manage billing, feature flags, or change member roles.

Member

Can access subscribed products and view their own account activity. Cannot manage the organization, members, or billing.

This exact reference is also shown live on the Team Members page in the portal, generated from the same permissions table the API routes enforce — the description here can't drift out of sync with what the system actually does.