Roles and permissions
Learn what the Owner, Admin, Editor and Viewer roles can do in Doxbrix, how workspace and project roles combine, and which roles use a paid seat.
Every person in a Doxbrix workspace has a role that decides what they can see and change. Read this page before you invite teammates, so you can give each person the access they need without handing out billing or security control, and without using paid seats you do not need.
Two levels of roles
Doxbrix assigns roles at two levels:
- Workspace role — one per member, set in Settings > Members & Invitations. It governs workspace administration: members, security, single sign-on, AI policy, billing and every project in the workspace.
- Project role — optional, set per project in the project's member settings. It governs operations inside that one project, such as managing its settings or its automation.
The Role Management section summarizes this as: “Workspace roles govern tenant administration. Project roles govern per-project operations.”
When the two levels differ, the more powerful one wins for project management. A workspace Owner or Admin can manage every project. A workspace Editor who is an Owner or Admin of a specific project can manage that project's settings and automation, but not other projects or the workspace.
Each role includes the abilities of the roles to its right in the chain, and adds the responsibilities shown below it.
The four workspace roles
| Role | What the role guide says | Uses an editor seat |
|---|---|---|
| Owner | Full access to all settings, billing, and member management. | Yes |
| Admin | Manage content, settings, and members. No billing access. | Yes |
| Editor | Create and edit content, manage categories and settings. | Yes |
| Viewer | View and search content. Cannot make changes. | No |
Owner
Owners have full workspace and project administration, including billing and security. Only an Owner can:
- change billing and plans (see Manage billing and change plans);
- grant the Owner or Admin role, or change another Owner or Admin;
- suspend, reactivate or remove an Admin;
- grant or modify project ownership, or remove another project Owner.
An Owner cannot be suspended or removed from Members & Invitations, and an Owner cannot demote themselves there. Keep at least two Owners so that the workspace is never locked out of billing.
Admin
Admins run the workspace day to day. They can save workspace settings, invite and manage Editors and Viewers, configure single sign-on and the AI policy, create agent tasks and manage every project. Admins have no billing access and cannot change another Owner or Admin.
Editor
Editors are the content operators. They create and edit pages, and they review content in the projects they belong to. Workspace settings stay with Owners and Admins. An Editor who is made Owner or Admin of a project can also manage that project's settings.
Viewer
Viewers read and search documentation and have read-only visibility into the settings sections and dashboards they are allowed to see. They cannot make changes. Viewers are the right role for stakeholders and for readers of a private site.
Seats and billing
Your plan includes a number of editor seats. Every active member with the Owner, Admin or Editor role uses one. Viewers never use an editor seat.
- Inviting or directly creating an Owner, Admin or Editor fails when no editor seat is free. Viewer invitations are not limited by editor seats.
- A Viewer who is given access to a private project counts as a private reader. Viewers of public projects are free and are not counted.
- Suspended members do not count toward editor seats, because only active members are counted.
See Plans and limits reference for the seat and private-reader limits of each plan.
Who can invite members
The Default invite restriction in Security basics decides who may send invitations:
| Setting | Who can invite |
|---|---|
| Workspace admins only (default) | Workspace Owners and Admins |
| Workspace owners only | Workspace Owners |
| Admins and project owners | Workspace Owners and Admins, plus anyone who owns at least one project in the workspace |
Whoever invites, only Owners can grant the Admin role, and Allowed email domains still limits which addresses can be invited. See Configure workspace settings.
Roles and page approvals
Roles decide who can work on a page; the project's approval policy decides who must approve it before it is published. With Review optional, authors can publish directly. With Review required or Owner approval, pages go through review first. New projects take their policy from Default review policy in Workspace Defaults. See Page lifecycle and approval policies and Submit, review and approve pages.
Member statuses
A member's Status in Workspace members also affects access:
- Active — the role applies normally.
- Suspended — no workspace access until reactivated. The role and project assignments are kept.
- Pending — the person signed in through single sign-on but has no role yet, so they cannot access the workspace until an Owner or Admin approves them.
- Invited people appear under Pending invitations until they accept.
Choose a role
- Give Viewer to anyone who only needs to read, including reviewers of a private site. It costs no editor seat.
- Give Editor to writers and reviewers.
- Give Admin to the few people who manage members, SSO and AI policy.
- Keep Owner for the people responsible for billing and for the workspace itself.
Every role change is recorded in Role Management > Recent role history.
