Northwind Insurance
Roles are organisation-wide and decide who can issue keys and who can spend money. A workspace has no members of its own.
Only one owner
Generated from the permission table the server enforces, so it cannot drift out of date.
| Can | Owner | Admin | Developer | Billing | Viewer |
|---|---|---|---|---|---|
| View keys | ✓ | ✓ | ✓ | · | ✓ |
| See key prefixes | ✓ | ✓ | ✓ | · | · |
| Create keys | ✓ | ✓ | ✓ | · | · |
| Edit keys | ✓ | ✓ | ✓ | · | · |
| Revoke keys | ✓ | ✓ | ✓ | · | · |
| Rotate keys | ✓ | ✓ | ✓ | · | · |
| Create workspaces | ✓ | ✓ | · | · | · |
| Edit workspaces | ✓ | ✓ | · | · | · |
| Delete workspaces | ✓ | ✓ | · | · | · |
| View guardrails | ✓ | ✓ | ✓ | · | ✓ |
| Set guardrails | ✓ | ✓ | · | · | · |
| View billing | ✓ | ✓ | · | ✓ | · |
| Change plans | ✓ | · | · | ✓ | · |
| Buy credits | ✓ | · | · | ✓ | · |
| Invite members | ✓ | ✓ | · | · | · |
| Change roles | ✓ | · | · | · | · |
| Remove members | ✓ | · | · | · | · |
| View request logs | ✓ | ✓ | ✓ | · | ✓ |
| View audit log | ✓ | ✓ | · | ✓ | ✓ |
| Enable products | ✓ | ✓ | · | · | · |
| Edit organisation | ✓ | · | · | · | · |
| Delete organisation | ✓ | · | · | · | · |
Owner
Full control, including billing and deleting the organisation.
Admin
Manages workspaces, keys and guardrails. Reads billing.
Developer
Creates and uses their own keys. Reads usage.
Billing
Manages plans, credits and invoices. No key access.
Viewer
Reads everything. Changes nothing. Key secrets stay masked.
Two things worth knowing