Skip to content
Endless Documentation

Permissions

Every permission a workspace enforces, and which of the four roles holds it.

Endless checks eleven permissions before it lets an action through. Which ones a person holds comes from their role, and the four roles work the same way in every workspace.

This table is generated from the permission catalog itself, so it can't fall behind what the product actually enforces. Roles and permissions explains the same list in prose, with the reasoning behind each one.

A role is a fixed set of abilities. There's no screen for handing a Viewer the ability to create content, or for taking billing away from an Admin — so this table is the whole story, in your workspace and everyone else's.

PermissionWhat it lets someone doAdminBilling managerMemberViewer
View and manage billingSee invoices and payment details, change the plan, and buy credit packs.YesYesNoNo
Invite and remove membersSend and revoke invitations, remove people, set their spending limits, and manage team membership.YesNoNoNo
Manage roles and permissionsChange which role each person in the workspace holds.YesNoNoNo
Change workspace settingsRename the workspace, change its logo and URL, manage teams, and delete it.YesNoNoNo
Create and edit contentChat, generate images and video, and create or edit canvases, projects, skills, transcripts and connectors.YesNoYesNo
Delete own contentTrash, restore, and permanently delete their own work.YesNoYesNo
Read content created by othersOpen other people's private projects, skills and scheduled tasks, including the chats those tasks produce.YesNoNoNo
Edit content created by othersChange someone else's shared work — projects, skills, connectors, scheduled tasks and published sites.YesNoNoNo
Delete content created by othersTrash and permanently delete the same.YesNoNoNo
View workspace activity and governanceSee the whole workspace's activity, and which models, features and tools each person can use — without changing any of it.YesNoNoNo
Change workspace governance settingsTurn models, features and tools on or off for the workspace, a team or one person, and change credit alert rules.YesNoNoNo

Admins hold everything

Admin is locked to the full list and can't be narrowed. That's the floor that stops a workspace configuring itself into having nobody who can manage its own settings — and it's why granting or removing Admin requires being an admin yourself, and why the last admin can't be demoted or removed.

Two pairs that look like one

Four rows above come in pairs, and the split is deliberate.

Viewing governance and changing it are separate. One permission opens the oversight surfaces — activity, and which models, features and tools each person can use — and reads them without touching anything. The other is what actually turns those things on and off. Kept apart so oversight can exist without the power to reconfigure: an auditor, a compliance reviewer, a team lead who should see everything and adjust nothing. Today only Admin holds either.

Editing someone else's work and deleting it are separate. One permission covering both would mean that trusting somebody to remove a colleague's work quietly also let them rewrite it. So they're two rows, and a role can hold one without the other.

Both pairs are about the workspace's shared things — projects, skills, connectors, scheduled tasks and published sites. Chats, canvases and assets belong to whoever made them; sharing one makes it readable, never editable, and no permission overrides that.

Where roles come from

Roles are assigned per person, per workspace, in Settings → Members. Everything about inviting people, changing someone's role, and what each role sees in Settings is in Workspaces and members and Roles and permissions.

On this page