Access control
Roles & Permissions
raia cX layers three independent role axes — platform, organization and agent. This page is the reference for what every role can do, which agents each role can see, how the axes combine into someone's effective access, and how roles are assigned.
What you will learn
- The three role axes and how a permission check is resolved
- What each of the eight roles is for
- The full organization and agent permission matrices
- What each role actually sees in the product
- How roles are granted, and who can grant which
How permissions work
A person's effective access to any resource is the union of what their roles grant on each axis. An organization role that already covers an agent cannot be narrowed by leaving the agent role off, and an agent role can grant access to someone whose organization role gives them nothing else.
Platform role
Everyone: standard account
Set per account. Every raia customer account is a plain user and gets no global power — all of a person's access comes from the two axes below.
Organization role
Owner · Admin · Manager · User · Copilot Admin · Copilot User · Guest
Set per organization membership. Drives the sidebar, which settings pages open, and default reach across all of the organization's agents.
Agent role
Owner · Admin · Editor · User · Copilot Admin · Copilot User
Set per agent, by direct invitation. It is an overlay: it can raise a person's access on one agent above what their organization role grants, never lower it.
Resolution order
- Membership first — the person's organization membership must be active before any role is evaluated.
- Organization actions (settings, members, billing, integrations) are checked against the organization role using the permission grid below.
- Agent actions use the direct agent role first; if that does not allow the action, the organization role on the agent.s organization is used instead. This is why Org Owners, Admins and Managers can manage agents they were never invited to.
- Ties go up. When both axes apply, the higher-ranked role wins. The ladder is Org Owner → Agent Owner → Org Admin → Agent Admin → Org Manager → Agent Editor → Org User → Agent User → Org Copilot Admin → Agent Copilot Admin → Org Copilot User → Agent Copilot User → Guest.
Launch Pad or Copilot
Each member sees one of two experiences: the full Launch Pad or the Copilot-only view. By default this follows their role — Copilot roles get the Copilot-only view — but it can be set per member, so someone with a Copilot role can be given Launch Pad, and vice versa.
Two things called “agent role”
A person's membership role on an agent (the subject of this page) is unrelated to the agent-persona catalog also called “Agent Roles” in the admin console — job titles such as “Support Agent”. Those carry no permissions.
Membership gate
Before any role is evaluated, the person's organization membership must be active. A suspended or inactive member sees nothing at all, whatever roles they hold.
The roles
Org Owner
Full control of the organization, including the only rights to delete the organization, grant the Owner role, edit invite restrictions, and remove members outside allowed email domains. Cannot be edited or removed by anyone else in the organization.
Org Admin
Everything an Owner does day to day: org settings, members and invitations, billing, API keys, brand, security, integrations, and all agents. Cannot delete the organization, grant Owner, or change owner-only security settings.
Org Manager
NewOperations lead without the keys. Full agent lifecycle (create, edit, delete, skills, training), conversations in admin mode, org statistics, logs, and a view of the member list — but no membership management, no billing and no org settings, and agent usage limits are read-only.
Org User
The standard builder seat. Launch Pad with Agents, Packs and Functions; can create agents (becoming their Agent Admin) and use Copilot. In Copilot they can see and chat with every active agent; in the Launch Pad they only see agents they created or were directly invited to. No org management, conversations overview or logs.
Copilot Admin
Copilot-only view with the Admin mode toggle: the admin conversation list, assigning conversations, changing conversation state, archiving, replying on behalf of the agent, and adding files to agent memory. No Launch Pad, no org settings, cannot create agents.
Copilot User
Copilot-only view, personal scope: chat with active agents and manage their own conversations and profile. No admin mode and no Launch Pad. Copilot roles cannot be invited onto individual agents.
Guest
NewThe most restricted seat, designed for outside collaborators invited to a specific agent. Lands on the Agents list and sees only agents they were directly invited to; Packs and Functions are hidden and they cannot create agents. Anyone invited to an agent who is not already an org member joins as a Guest automatically.
On any single agent, a direct membership adds one of six roles on top of the organization role: Agent Owner (full control including delete), Agent Admin (everything but delete and granting Owner), Agent Editor (configure, train and run — no members or limits), Agent User (use the agent, view Info, Launch and Report), and Agent Copilot Admin / Copilot User (Copilot surface only, with and without admin mode).
Organization permission matrix
What each organization role may do, as enforced by the API. A direct agent role can additionally unlock agent-scoped rows for specific agents.
| Capability | Owner | Admin | Manager | User | Copilot Admin | Copilot User | Guest |
|---|---|---|---|---|---|---|---|
| Organization & settings | |||||||
| View organization | ✓ | ✓ | ✓ | ✓ | ✕ | ✕ | ✓ |
| Edit organization settings | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Security & 2FA policy, allowed email domains | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Invite restrictions setting | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Org & default limits, license key | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Delete organization | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Members | |||||||
| View member list | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Invite / edit / remove members | ✓ | ✓invite obeys owner-only restriction | ✕ | ✕ | ✕ | ✕ | ✕ |
| Grant org roles | ◐any role, incl. Owner | ◐any role except Owner | ✕ | ✕ | ✕ | ✕ | ✕ |
| Access Matrix (users × agents) | ✓ | ✓ | ◐edit roles; cannot revoke | ✕ | ✕ | ✕ | ✕ |
| Agents | |||||||
| Create / import agent | ✓ | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ |
| See org agents | ✓all statuses | ✓all statuses | ✓all statuses | ◐all active agents in Copilot; own + invited in Launch Pad | ◐active only | ◐active only | ◐invited only |
| Edit / delete agents, skills, training, webhooks | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Edit agent usage limits | ✓ | ✓ | ◐view only | ✕ | ✕ | ✕ | ✕ |
| Manage agent members | ✓ | ✓ | ◐existing org members only | ✕ | ✕ | ✕ | ✕ |
| Conversations & Copilot | |||||||
| Chat with agents (Copilot) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ◐only via an agent role |
| Admin mode: view all conversations, assign, set state, reply as agent | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ | ✕ |
| Conversations & conversation-user pages (Launch Pad) | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Org conversation states | ✓ | ✓ | ◐read only | ✕ | ✕ | ✕ | ✕ |
| Packs & functions | |||||||
| View packs & functions | ✓ | ✓ | ✓ | ✓ | ✕ | ✕ | ✕UI hidden |
| Create / edit / clone packs & functions | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Create global packs / functions | ✕raia support only | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Billing, keys & integrations | |||||||
| View subscription & usage | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Pay / change / cancel subscription, view payments | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Org API keys, external-service keys, custom domains | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Slack / Microsoft integrations | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Insight | |||||||
| Org statistics, logs, resource usage | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Feedback export | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ | ✕ |
| Download training documents | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
Some platform-wide capabilities sit outside organization roles entirely — creating organizations, global packs and functions, subscription-plan administration, and LLM model configuration are handled by raia support on request.
Agent-role matrix
Granted by direct invitation to one agent, on top of the organization role. If the agent role does not allow an action, the organization role is considered next — so these columns matter most for Org Users and Guests, whose organization role grants little.
| Capability (this agent) | Owner | Admin | Editor | User | Copilot Admin | Copilot User |
|---|---|---|---|---|---|---|
| View agent, Info & Launch tabs | ✓ | ✓ | ✓ | ✓ | ◐Copilot surface | ◐Copilot surface |
| Edit configuration, skills, training | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ |
| Usage & Security tabs, edit limits | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Delete agent | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Invite / manage agent members | ◐grant any role | ◐grant all but Owner | ✕ | ✕ | ✕ | ✕ |
| Chat, own conversations | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Admin mode on conversations | ✓ | ✓ | ✓ | ✓ | ✓ | ✕ |
| Reply on behalf of the agent | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ |
| Escalations & alerts | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ |
| Add files to agent memory | ✓ | ✓ | ✓ | ✕ | ✓ | ✕ |
| Agent reports | ✓ | ✓ | ✕ | ✓ | ✕ | ✕ |
Read-only mode
A member who holds the Agent User role and is only an Org User or Guest in the organization sees the agent in read-only: forms, toggles and status controls appear disabled across Info, Launch and conversation-state views.
What each role sees
How the same rules land in navigation and daily use. This is the answer to most access questions: someone has been added to the organization but their agent list is empty, because their organization role is scoped and they hold no agent role.
| Experience | Owner | Admin | Manager | User | Copilot Admin | Copilot User | Guest |
|---|---|---|---|---|---|---|---|
| Shell & landing page | ◐Launch Pad · Dashboard | ◐Launch Pad · Dashboard | ◐Launch Pad · Dashboard | ◐Launch Pad · Dashboard | ◐Copilot only | ◐Copilot only | ◐Launch Pad · Agents list |
| Sidebar: Agents | ✓ | ✓ | ✓ | ◐own + invited agents | ✕ | ✕ | ✓ |
| Sidebar: Packs & Functions | ✓ | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ |
| Sidebar: Users, Conversations, Logs, Usage | ✓ | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ |
| Settings: API Keys, Brand, Security, Limits | ✓ | ✓ | ✕ | ✕ | ✕ | ✕ | ✕ |
| Copilot access | ✓ | ✓ | ✓ | ✓all active agents | ✓ | ✓ | ✓invited agents |
| Copilot admin-mode toggle | ✓ | ✓ | ✓ | ◐with an agent role | ✓ | ✕ | ◐with an agent role |
| Member actions on Org Users page | ✓ | ✓ | ◐visible, disabled | ✕ | ✕ | ✕ | ✕ |
- Managers see the Org Users page with every action button disabled, and agent usage limits as a read-only panel.
- Nobody can edit themselves or an Org Owner in the member table, and role changes applied to yourself are rejected.
- The Access Matrix page (Settings → Org Users → Access Matrix) is currently behind a feature toggle that is off by default.
How roles are assigned
| Path | What happens | Role granted |
|---|---|---|
| Sign-up | A self-registered user becomes Org Owner of a newly created organization. | Org Owner |
| Org invitation | Owners and Admins choose the role at invite time. The dropdown offers Admin, Manager, User, Copilot Admin, Copilot User and Guest — Owner is never assignable by invite; only an Owner can promote someone to Owner afterwards. | Any role except Owner |
| Agent invitation | Owners, Admins and Managers can add people to a single agent with any agent role (Agent Owner is grantable by an Org Owner/Admin or the current Agent Owner only). Managers can only add people who are already org members. | Agent Owner / Admin / Editor / User |
| Agent invitation to a new email | Inviting an address that is not yet in the organization auto-creates an org membership as Guest. This is the intended entry path for outside collaborators. | Guest |
| Invite restrictions | An Owner can restrict invitations to Owners only and/or to allowed email domains, and can bulk-remove members whose email falls outside the allowed domains. | Owner only |
Copilot roles cannot hold agent seats
Inviting someone whose organization role is Copilot Admin or Copilot User onto an individual agent is rejected. Give them a Launch Pad role first if they need a per-agent grant.
Where to change roles
Organization roles
Organization Management → Users. Owners can assign any role; Admins can assign every role except Owner.
Agent roles
Launch Pad → the agent → Security tab. Roles apply to that agent only, and an inactive row hides the agent just as effectively as no row at all.
Who owns a new agent
When an Org Owner creates an agent they become its Agent Owner. When anyone else creates one, they become Agent Admin and the Org Owner becomes Agent Owner — so ownership always stays with the organization.
Server-side enforcement
Every rule above is enforced by the API. Navigation and hidden buttons are a convenience layer only — a role change takes effect on the server the moment it is saved.
Related reading: Security → Roles & access control and the Launch Pad guide.