Roles and permissions
The four roles a workspace has, exactly what each one can do, and the rules that stop a workspace from locking itself out.
Every person in a workspace holds a role, and that role decides what they can do. Behind each role sits a set of permissions — eleven of them, one for each thing Endless checks before it lets an action through.
The four roles work the same way in every workspace. A Member here can do exactly what a Member can do anywhere else on Endless, so "make them a Member" means the same thing to everyone. Workspaces and members covers how roles sit alongside teams, invitations and the member directory; this page is the detail underneath.
The four roles
Admin
Full access, always. Every permission, and everything administrative — inviting people, changing roles, workspace settings, governance.
Member
The everyday role. Create and edit content, and delete their own.
Billing manager
Billing and nothing else — for a finance contact who shouldn't have operational access.
Viewer
Read-only. They can see what's been shared with them, but can't create anything or spend the workspace's credits.
A role is a fixed set of abilities, not a starting point you tune. There is no screen for handing a Viewer the ability to create content, or for taking billing away from an admin. If someone needs to do more, give them the role that covers it.
The permissions
Every role's abilities come from this list. Held by is the whole story — no workspace differs.
| Permission | What it lets someone do | Held by |
|---|---|---|
| View and manage billing | See invoices and payment details, change the plan, buy credit packs | Admin, Billing manager |
| Invite and remove members | Send and revoke invitations, remove people, set their spending limits, manage team membership | Admin |
| Manage roles and permissions | Change which role each person in the workspace holds | Admin |
| Change workspace settings | Rename the workspace, change its logo and URL, manage teams, delete it | Admin |
| Create and edit content | Chat, generate images and video, and create or edit canvases, projects, skills, transcripts and connectors | Admin, Member |
| Delete own content | Trash, restore, and permanently delete their own work | Admin, Member |
| Read content created by others | Open other people's private projects, skills and scheduled tasks, including the chats those tasks produce | Admin |
| Edit content created by others | Change someone else's shared work — projects, skills, connectors, scheduled tasks, published sites | Admin |
| Delete content created by others | Trash and permanently delete the same | Admin |
| View workspace activity and governance | See the whole workspace's activity, and which models, features and tools each person can use | Admin |
| Change workspace governance settings | Turn models, features and tools on or off for the workspace, a team or one person; change credit alert rules | Admin |
"Create and edit content" is the broad one. Without it — which means Viewer and Billing manager — a person can't chat, generate images or video, or create canvases, projects or skills. It also covers drawing: a Viewer can open a canvas that's been shared with them, sees a "Read-only" badge in its header, and their edits are refused.
Own work vs. everyone's work
Four of these come in pairs, and the distinction is deliberate:
Editing
"Create and edit content" covers a person's own work. "Edit content created by others" is what extends that to the whole workspace.
Deleting
"Delete own content" and "Delete content created by others" split the same way — so someone can tidy up after themselves without being able to remove a colleague's work. Two separate permissions, so being trusted to delete someone's work never quietly grants the ability to rewrite it instead.
The two "created by others" permissions cover the workspace's shared things: projects, skills, connectors, scheduled tasks and published sites. Chats, canvases, assets and generations belong to the person who made them and stay that way — nobody else can edit or delete them, and no permission overrides that. Sharing one makes it readable, never editable.
Looking vs. changing
View workspace activity and governance
Read-only oversight: the activity feed, and which models and tools each person can use.
Change workspace governance settings
Actually turning models, features and tools on or off, and changing the credit alert rules.
These are two permissions rather than one so that oversight can exist without the power to reconfigure — an auditor, a compliance reviewer, or a team lead who should see everything and adjust nothing. Today only Admin holds either.
Reading private content is its own permission too. "Read content created by others" is the oversight escape hatch for a workspace's automations — a runaway private scheduled task, or someone's projects and skills after they leave. It stops there: private chats, canvases and assets stay with whoever made them, and no role opens those. See Assets and visibility.
What each role sees in Settings
The whole Settings → Governance section — activity, models, features, tools, alerts — requires the permission to view workspace activity and governance. Teams, inside that same section, requires the permission to change workspace settings instead, not in addition.
Neither belongs to Member, Billing manager or Viewer, so for all three the section simply isn't in the settings menu, and following an old link to one of its pages lands them on Settings → Account.
Settings → Members is different: everyone can open it and everyone sees the same roster, including how many credits each person has used this cycle. What changes with your role is the controls — invite, change a role, set a spending limit, remove someone — and they're hidden rather than refused.
Admins are always admins
Admin holds every permission, and that can't be narrowed. In the product: "Admins always have every permission — that can't be changed."
This is the floor that stops a workspace locking itself out of its own settings. Two related rules follow from it:
Only admins make admins
Nobody can hand out a role they don't hold themselves. Granting or removing Admin requires being an admin — so it isn't an assignment like any other. That applies to invitations too: only an admin can invite someone straight in as an admin.
The last admin stays
A workspace always keeps at least one admin. The last one can't be demoted or removed, and can't leave the workspace until someone else is promoted.
Inviting people
Sending invitations requires "Invite and remove members", which only Admin holds. If a teammate can't invite anyone, that's why — the Invite button isn't hidden by accident, and making them an admin is what changes it.
Invitations carry the role the new person will hold, and the role picker offers only what the inviter can assign. Everything about inviting, accepting and revoking is in Workspaces and members.
Choosing a role
- A finance contact who pays the bills and sees nothing else → Billing manager. They get billing, and no operational access at all.
- A contractor or teammate producing work → Member. They can chat, generate, and create canvases, projects and skills, and clean up after themselves — but can't edit or delete a colleague's shared work, can't invite anyone, and can't see the workspace's private content.
- A stakeholder who should follow along without spending credits → Viewer. They can open what's been shared with them and nothing more.
- Anyone who needs to run the workspace — invite people, change roles, govern which models and tools it uses → Admin. Keep this list short: Admin is everything, permanently.