Roles and permissions

Updated Aug 31, 2026·2 min read

Everyone in an organization holds one role in it: Owner, Admin, Editor or Viewer. The role decides what that person can do with the organization's simulations, sandboxes, people and money.

Roles are per organization. Being an owner of one says nothing about your role in another.

The four roles

  • Owner runs the organization, the plan and the payments.
  • Admin runs the team and the settings, but never the money.
  • Editor builds: simulations, sandboxes, deploys, support.
  • Viewer reads.

What each role can do

TaskOwnerAdminEditorViewer
See simulations, history, replays and usageYesYesYesYes
Read support issuesYesYesYesYes
Create, edit and deploy simulationsYesYesYesNo
Create and run sandboxesYesYesYesNo
Open and answer support issuesYesYesYesNo
Invite members and change their rolesYesYesNoNo
Create and revoke API keysYesYesNoNo
Change the organization name and URLYesYesNoNo
Set the simulation access defaultsYesYesNoNo
Read the audit logYesYesNoNo
Set up single sign-onYesNoNoNo
Buy providers for a sandboxYesNoNoNo
Change the plan, pay and read invoicesYesNoNoNo
Delete the organizationYesNoNoNo

An admin cannot change or remove an owner, and only an owner can hand out the owner role. An organization always keeps at least one owner.

Roles on a single simulation

Members reach every simulation in the organization at the role they hold there.

You can also share one simulation with someone outside the organization. They get a role on that simulation alone: owner, editor or viewer of it, and nothing else in the organization.

See Share links.

Roles on API keys

A key carries a role of its own, and it stops at editor. A key can read and deploy. It can never manage people, other keys, or billing.

See API keys.

Changing a role

Owners and admins change roles in Settings, on the Members tab.

See Members and invitations.

Was this page helpful?