Skip to content
← All products

Access control

Roles & Permissions

raia cX layers three independent role axes — platform, organization and agent. This page is the reference for what every role can do, which agents each role can see, how the axes combine into someone's effective access, and how roles are assigned.

What you will learn

  • The three role axes and how a permission check is resolved
  • What each of the eight roles is for
  • The full organization and agent permission matrices
  • What each role actually sees in the product
  • How roles are granted, and who can grant which
01

How permissions work

A person's effective access to any resource is the union of what their roles grant on each axis. An organization role that already covers an agent cannot be narrowed by leaving the agent role off, and an agent role can grant access to someone whose organization role gives them nothing else.

Platform role

Everyone: standard account

Set per account. Every raia customer account is a plain user and gets no global power — all of a person's access comes from the two axes below.

Organization role

Owner · Admin · Manager · User · Copilot Admin · Copilot User · Guest

Set per organization membership. Drives the sidebar, which settings pages open, and default reach across all of the organization's agents.

Agent role

Owner · Admin · Editor · User · Copilot Admin · Copilot User

Set per agent, by direct invitation. It is an overlay: it can raise a person's access on one agent above what their organization role grants, never lower it.

Resolution order

  • Membership first — the person's organization membership must be active before any role is evaluated.
  • Organization actions (settings, members, billing, integrations) are checked against the organization role using the permission grid below.
  • Agent actions use the direct agent role first; if that does not allow the action, the organization role on the agent.s organization is used instead. This is why Org Owners, Admins and Managers can manage agents they were never invited to.
  • Ties go up. When both axes apply, the higher-ranked role wins. The ladder is Org Owner → Agent Owner → Org Admin → Agent Admin → Org Manager → Agent Editor → Org User → Agent User → Org Copilot Admin → Agent Copilot Admin → Org Copilot User → Agent Copilot User → Guest.

Launch Pad or Copilot

Each member sees one of two experiences: the full Launch Pad or the Copilot-only view. By default this follows their role — Copilot roles get the Copilot-only view — but it can be set per member, so someone with a Copilot role can be given Launch Pad, and vice versa.

Two things called “agent role”

A person's membership role on an agent (the subject of this page) is unrelated to the agent-persona catalog also called “Agent Roles” in the admin console — job titles such as “Support Agent”. Those carry no permissions.

Membership gate

Before any role is evaluated, the person's organization membership must be active. A suspended or inactive member sees nothing at all, whatever roles they hold.

02

The roles

Org Owner

Full control of the organization, including the only rights to delete the organization, grant the Owner role, edit invite restrictions, and remove members outside allowed email domains. Cannot be edited or removed by anyone else in the organization.

Org Admin

Everything an Owner does day to day: org settings, members and invitations, billing, API keys, brand, security, integrations, and all agents. Cannot delete the organization, grant Owner, or change owner-only security settings.

Org Manager

New

Operations lead without the keys. Full agent lifecycle (create, edit, delete, skills, training), conversations in admin mode, org statistics, logs, and a view of the member list — but no membership management, no billing and no org settings, and agent usage limits are read-only.

Org User

The standard builder seat. Launch Pad with Agents, Packs and Functions; can create agents (becoming their Agent Admin) and use Copilot. In Copilot they can see and chat with every active agent; in the Launch Pad they only see agents they created or were directly invited to. No org management, conversations overview or logs.

Copilot Admin

Copilot-only view with the Admin mode toggle: the admin conversation list, assigning conversations, changing conversation state, archiving, replying on behalf of the agent, and adding files to agent memory. No Launch Pad, no org settings, cannot create agents.

Copilot User

Copilot-only view, personal scope: chat with active agents and manage their own conversations and profile. No admin mode and no Launch Pad. Copilot roles cannot be invited onto individual agents.

Guest

New

The most restricted seat, designed for outside collaborators invited to a specific agent. Lands on the Agents list and sees only agents they were directly invited to; Packs and Functions are hidden and they cannot create agents. Anyone invited to an agent who is not already an org member joins as a Guest automatically.

On any single agent, a direct membership adds one of six roles on top of the organization role: Agent Owner (full control including delete), Agent Admin (everything but delete and granting Owner), Agent Editor (configure, train and run — no members or limits), Agent User (use the agent, view Info, Launch and Report), and Agent Copilot Admin / Copilot User (Copilot surface only, with and without admin mode).

03

Organization permission matrix

What each organization role may do, as enforced by the API. A direct agent role can additionally unlock agent-scoped rows for specific agents.

allowed denied partial — see the note in the cell
CapabilityOwnerAdminManagerUserCopilot AdminCopilot UserGuest
Organization & settings
View organization
Edit organization settings
Security & 2FA policy, allowed email domains
Invite restrictions setting
Org & default limits, license key
Delete organization
Members
View member list
Invite / edit / remove members
invite obeys owner-only restriction
Grant org roles
any role, incl. Owner
any role except Owner
Access Matrix (users × agents)
edit roles; cannot revoke
Agents
Create / import agent
See org agents
all statuses
all statuses
all statuses
all active agents in Copilot; own + invited in Launch Pad
active only
active only
invited only
Edit / delete agents, skills, training, webhooks
Edit agent usage limits
view only
Manage agent members
existing org members only
Conversations & Copilot
Chat with agents (Copilot)
only via an agent role
Admin mode: view all conversations, assign, set state, reply as agent
Conversations & conversation-user pages (Launch Pad)
Org conversation states
read only
Packs & functions
View packs & functions
UI hidden
Create / edit / clone packs & functions
Create global packs / functions
raia support only
Billing, keys & integrations
View subscription & usage
Pay / change / cancel subscription, view payments
Org API keys, external-service keys, custom domains
Slack / Microsoft integrations
Insight
Org statistics, logs, resource usage
Feedback export
Download training documents

Some platform-wide capabilities sit outside organization roles entirely — creating organizations, global packs and functions, subscription-plan administration, and LLM model configuration are handled by raia support on request.

04

Agent-role matrix

Granted by direct invitation to one agent, on top of the organization role. If the agent role does not allow an action, the organization role is considered next — so these columns matter most for Org Users and Guests, whose organization role grants little.

allowed denied partial — see the note in the cell
Capability (this agent)OwnerAdminEditorUserCopilot AdminCopilot User
View agent, Info & Launch tabs
Copilot surface
Copilot surface
Edit configuration, skills, training
Usage & Security tabs, edit limits
Delete agent
Invite / manage agent members
grant any role
grant all but Owner
Chat, own conversations
Admin mode on conversations
Reply on behalf of the agent
Escalations & alerts
Add files to agent memory
Agent reports

Read-only mode

A member who holds the Agent User role and is only an Org User or Guest in the organization sees the agent in read-only: forms, toggles and status controls appear disabled across Info, Launch and conversation-state views.

05

What each role sees

How the same rules land in navigation and daily use. This is the answer to most access questions: someone has been added to the organization but their agent list is empty, because their organization role is scoped and they hold no agent role.

allowed denied partial — see the note in the cell
ExperienceOwnerAdminManagerUserCopilot AdminCopilot UserGuest
Shell & landing page
Launch Pad · Dashboard
Launch Pad · Dashboard
Launch Pad · Dashboard
Launch Pad · Dashboard
Copilot only
Copilot only
Launch Pad · Agents list
Sidebar: Agents
own + invited agents
Sidebar: Packs & Functions
Sidebar: Users, Conversations, Logs, Usage
Settings: API Keys, Brand, Security, Limits
Copilot access
all active agents
invited agents
Copilot admin-mode toggle
with an agent role
with an agent role
Member actions on Org Users page
visible, disabled
  • Managers see the Org Users page with every action button disabled, and agent usage limits as a read-only panel.
  • Nobody can edit themselves or an Org Owner in the member table, and role changes applied to yourself are rejected.
  • The Access Matrix page (Settings → Org Users → Access Matrix) is currently behind a feature toggle that is off by default.
06

How roles are assigned

PathWhat happensRole granted
Sign-upA self-registered user becomes Org Owner of a newly created organization.Org Owner
Org invitationOwners and Admins choose the role at invite time. The dropdown offers Admin, Manager, User, Copilot Admin, Copilot User and Guest — Owner is never assignable by invite; only an Owner can promote someone to Owner afterwards.Any role except Owner
Agent invitationOwners, Admins and Managers can add people to a single agent with any agent role (Agent Owner is grantable by an Org Owner/Admin or the current Agent Owner only). Managers can only add people who are already org members.Agent Owner / Admin / Editor / User
Agent invitation to a new emailInviting an address that is not yet in the organization auto-creates an org membership as Guest. This is the intended entry path for outside collaborators.Guest
Invite restrictionsAn Owner can restrict invitations to Owners only and/or to allowed email domains, and can bulk-remove members whose email falls outside the allowed domains.Owner only

Copilot roles cannot hold agent seats

Inviting someone whose organization role is Copilot Admin or Copilot User onto an individual agent is rejected. Give them a Launch Pad role first if they need a per-agent grant.

07

Where to change roles

Organization roles

Organization Management → Users. Owners can assign any role; Admins can assign every role except Owner.

Agent roles

Launch Pad → the agent → Security tab. Roles apply to that agent only, and an inactive row hides the agent just as effectively as no row at all.

Who owns a new agent

When an Org Owner creates an agent they become its Agent Owner. When anyone else creates one, they become Agent Admin and the Org Owner becomes Agent Owner — so ownership always stays with the organization.

Server-side enforcement

Every rule above is enforced by the API. Navigation and hidden buttons are a convenience layer only — a role change takes effect on the server the moment it is saved.