> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

Every member is assigned one role, which is a fixed set of permissions. You should only ever assign a member the narrowest role that lets them accomplish their job.

## Roles

| Role            | Purpose                                                                                                                    | Assignable                             |
| --------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------- |
| Owner           | Accountable for the workspace. Full control, including billing and workspace settings.                                     | Only set when the workspace is created |
| Admin           | Manages connections, mappings, policies, secrets, and members. No billing or workspace settings access.                    | Yes                                    |
| Billing manager | Handles the subscription, invoices, and AI credits. Otherwise, has read-only access to the workspace and worker directory. | Yes                                    |
| Member          | Runs syncs, approves plans, and decides how accounts are adopted. **Cannot set up connections or write policies.**         | Yes                                    |
| Audit           | Read-only access to the workspace.                                                                                         | Yes                                    |
| Support         | Klef staff troubleshooting your workspace.                                                                                 | No                                     |

Assigning roles requires the `Manage members` permission, which only the **Owner** and **Admin** roles have. When you [invite someone or change their role](/docs/how-to/manage-members), you can assign any role except for **Owner** and **Support**.

Only an owner can change or remove another owner, and a workspace requires at least one owner, so the last owner cannot be removed or have their role changed.

## Permissions

| Permission                   | Allows                                                     |
| ---------------------------- | ---------------------------------------------------------- |
| `View workspace`             | Read-only access to the workspace and its settings.        |
| `Manage connections`         | Connect, configure, and disconnect connectors.             |
| `Manage mapping`             | Edit field mappings.                                       |
| `Manage policies`            | Create and edit policies and resources.                    |
| `Manage secrets`             | Create, edit, delete, and reveal workspace secrets.        |
| `Run syncs`                  | Request and approve sync plans.                            |
| `Resolve matches`            | Resolve a worker to an existing account.                   |
| `View workers`               | Read-only access to the worker directory.                  |
| `View audit log`             | Read-only access to the audit log.                         |
| `Manage members`             | Invite, remove, and change members' roles.                 |
| `Manage billing`             | Manage the subscription and payment.                       |
| `Manage workspace lifecycle` | Change workspace settings, export its data, and delete it. |

## What Each Role Can Do

| Role            | Permissions                                                                                                                                                                       |
| --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Owner           | Every permission.                                                                                                                                                                 |
| Admin           | `View workspace`, `Manage connections`, `Manage mapping`, `Manage policies`, `Manage secrets`, `Run syncs`, `Resolve matches`, `View workers`, `View audit log`, `Manage members` |
| Billing manager | `View workspace`, `View workers`, `Manage billing`                                                                                                                                |
| Member          | `View workspace`, `View workers`, `Run syncs`, `Resolve matches`, `View audit log`                                                                                                |
| Audit           | `View workspace`, `View workers`, `View audit log`                                                                                                                                |
| Support         | `View workspace`, `Manage connections`, `Manage mapping`, `Manage policies`, `Manage secrets`, `Run syncs`, `Resolve matches`, `View workers`, `View audit log`                   |
