Skip to main content
This chapter is a quick-reference cheat sheet. Roles are additive and the highest one wins, so an Org Admin who is also a Department Employee always acts with Org Admin rights.

How to read this table

  • Yes — the role can do this anywhere within its scope.
  • No — not available to this role.
  • Conditional — allowed only in specific situations.
  • “Resource” means any shareable item: dashboard, data source, file, folder, chat, or agent.

Capability matrix

ActionOrg OwnerOrg AdminDept AdminDept ManagerDept Employee (Member)
Create resourcesYesYesYesYesConditional — must belong to a department
View own resourcesYesYesYesYesYes
View resources shared with youYesYesYesYesYes
View others’ personal resources (admin view)YesYesNoNoNo
Share as ViewerConditionalConditionalConditionalConditionalConditional
Share as EditorConditionalConditionalConditionalConditionalConditional
Edit a resource shared with youConditional — only if Editor or ownerConditionalConditionalConditionalConditional
Delete / move resource to TrashConditional — ownerConditionalConditionalConditional — owner onlyConditional — owner only
Restore from TrashConditional — within 3-day windowConditionalConditionalConditionalConditional
Transfer resource ownershipConditional — current owner onlyConditionalConditionalConditionalConditional
Manage department membersYesYesConditional — own departmentNoNo
Create / edit departmentsYesYesNoNoNo
Invite org membersYesYesNoNoNo
Remove org membersYesYesNoNoNo
Toggle org-wide external sharingYesYesNoNoNo
Manage billing (plans, budgets, payment)YesYesNoNoNo
Curate AI models & toolsYesYesNoNoNo
View audit log / implicit-access feedYesYesNoNoNo

Notes on the conditional cells

  • Sharing and editing depend on your relationship to the specific resource. You can only share at or below your own level. External sharing requires the org-wide external-sharing toggle to be on.
  • External users are always view-only and can never re-share.
  • Delete, restore, and transfer ownership are tied to being the resource’s owner.
  • Admin view (implicit access) requires acknowledgement and is audited every use.
  • Creating resources requires department membership.
  • Department Managers cannot manage members or create departments.