Skip to main content
Docs
Permissions

Permissions

Understand roles and permissions for organization members.

Elyxir uses role-based access control (RBAC) to manage what users can do within an organization. Each role has specific permissions.

Roles

Owner

The organization creator with full control:

  • All Admin permissions
  • Manage billing and subscription
  • Delete the organization
  • Transfer ownership
  • Cannot be removed

Limit: One owner per organization

Admin

Organization administrators who can:

  • Invite and remove members
  • Change member roles (except Owner)
  • Create and manage API keys
  • View all analytics
  • Update organization settings

Member

Standard team members who can:

  • Use Studio features (chat, Model Hub)
  • View their own analytics
  • Access shared resources
  • Cannot manage team or settings

Permission Matrix

PermissionOwnerAdminMember
Use Studio chat
Browse Model Hub
View own analytics
View all analytics
Create API keys
Manage API keys
Invite members
Remove members
Change member roles✓*
Update org settings
Manage billing
Delete organization
Transfer ownership

*Admins cannot change the Owner role

Role Assignment

Initial Assignment

When inviting a new member:

  1. Enter their email
  2. Select role (Admin or Member)
  3. Send invitation

Changing Roles

To change an existing member's role:

  1. Go to Settings > Organization > Members
  2. Find the member
  3. Click role dropdown
  4. Select new role

Role Change Rules

  • Only Owners can promote to Admin
  • Owners cannot be demoted
  • Admins can promote Members to Admin
  • Admins cannot demote other Admins

Ownership Transfer

To transfer organization ownership:

  1. Must be current Owner
  2. Go to Settings > Organization > General
  3. Click Transfer Ownership
  4. Select new Owner
  5. Confirm with password

Permissions by Feature

Studio Chat

ActionOwnerAdminMember
Send messages
Select models
View history

API Keys

ActionOwnerAdminMember
Create keys
View keys
Revoke keys
Set limits

Analytics

ActionOwnerAdminMember
View own usage
View org usage
View costs
Export data

Billing

ActionOwnerAdminMember
View invoices
Update payment
Change plan
View usage

Security Best Practices

  1. Minimize Admin access: Only give Admin to those who need it
  2. Regular audits: Review roles quarterly
  3. Principle of least privilege: Start with Member, upgrade as needed
  4. Ownership backup: Ensure continuity if Owner leaves
Permissions | elyxir