Permissions
Every permission a workspace enforces, and which of the four roles holds it.
Endless checks eleven permissions before it lets an action through. Which ones a person holds comes from their role, and the four roles work the same way in every workspace.
This table is generated from the permission catalog itself, so it can't fall behind what the product actually enforces. Roles and permissions explains the same list in prose, with the reasoning behind each one.
A role is a fixed set of abilities. There's no screen for handing a Viewer the ability to create content, or for taking billing away from an Admin — so this table is the whole story, in your workspace and everyone else's.
| Permission | What it lets someone do | Admin | Billing manager | Member | Viewer |
|---|---|---|---|---|---|
| View and manage billing | See invoices and payment details, change the plan, and buy credit packs. | Yes | Yes | No | No |
| Invite and remove members | Send and revoke invitations, remove people, set their spending limits, and manage team membership. | Yes | No | No | No |
| Manage roles and permissions | Change which role each person in the workspace holds. | Yes | No | No | No |
| Change workspace settings | Rename the workspace, change its logo and URL, manage teams, and delete it. | Yes | No | No | No |
| Create and edit content | Chat, generate images and video, and create or edit canvases, projects, skills, transcripts and connectors. | Yes | No | Yes | No |
| Delete own content | Trash, restore, and permanently delete their own work. | Yes | No | Yes | No |
| Read content created by others | Open other people's private projects, skills and scheduled tasks, including the chats those tasks produce. | Yes | No | No | No |
| Edit content created by others | Change someone else's shared work — projects, skills, connectors, scheduled tasks and published sites. | Yes | No | No | No |
| Delete content created by others | Trash and permanently delete the same. | Yes | No | No | No |
| View workspace activity and governance | See the whole workspace's activity, and which models, features and tools each person can use — without changing any of it. | Yes | No | No | No |
| Change workspace governance settings | Turn models, features and tools on or off for the workspace, a team or one person, and change credit alert rules. | Yes | No | No | No |
Admins hold everything
Admin is locked to the full list and can't be narrowed. That's the floor that stops a workspace configuring itself into having nobody who can manage its own settings — and it's why granting or removing Admin requires being an admin yourself, and why the last admin can't be demoted or removed.
Two pairs that look like one
Four rows above come in pairs, and the split is deliberate.
Viewing governance and changing it are separate. One permission opens the oversight surfaces — activity, and which models, features and tools each person can use — and reads them without touching anything. The other is what actually turns those things on and off. Kept apart so oversight can exist without the power to reconfigure: an auditor, a compliance reviewer, a team lead who should see everything and adjust nothing. Today only Admin holds either.
Editing someone else's work and deleting it are separate. One permission covering both would mean that trusting somebody to remove a colleague's work quietly also let them rewrite it. So they're two rows, and a role can hold one without the other.
Both pairs are about the workspace's shared things — projects, skills, connectors, scheduled tasks and published sites. Chats, canvases and assets belong to whoever made them; sharing one makes it readable, never editable, and no permission overrides that.
Where roles come from
Roles are assigned per person, per workspace, in Settings → Members. Everything about inviting people, changing someone's role, and what each role sees in Settings is in Workspaces and members and Roles and permissions.