Roles and permissions
| Action | Owner | Admin | Member |
|---|---|---|---|
| View organisation resources | Yes | Yes | Yes |
| Create/edit own workflows | Yes | Yes | Limited by current product rules |
| Register or replace contract capabilities | Yes | Yes | No |
| Invite/remove regular members | Yes | Yes | No |
| Promote/demote or remove admins | Yes | No | No |
| Manage billing and seats | Yes | Limited where shown | No |
| Delete a standard organisation | Owner-only where supported | No | No |
| Mutate a personal organisation’s membership | No | No | No |
A role is not enough by itself. The user must also have a current seat, verified email when required, resource ownership where applicable, and the correct wallet/Safe authority for execution.
Agent credentials never elevate their owner. They impose an additional immutable scope and account-grant ceiling, and every request rechecks the owner’s current authority.
Product controls can further narrow an action. Read the confirmation dialog and error message shown for the specific resource.