Permission Recommendations
Understand the workspace roles in Odeus and how access is granted across products and shared resources.
Permission Recommendations
Understand the workspace roles in Odeus and how access is granted across products and shared resources.
Workspace Roles
Odeus uses role-based access control (RBAC) with four roles:
- Owner: Full control of the workspace, including billing and deletion.
- Admin: Manage workspace settings, members, models, and the Knowledge Hub.
- Billing: Manage the plan, invoices, and the subscription portal.
- Member: Standard user access for everyday work.
Roles are assigned per member in member settings.
What Each Role Can Do
| Capability | Member | Admin | Billing | Owner |
|---|---|---|---|---|
| Chat, Deep Research, use agents | ✓ | ✓ | ✓ | ✓ |
| Create agents, workflows, and skills | ✓ | ✓ | ✓ | ✓ |
| Upload documents to the Knowledge Hub | ✓ | ✓ | ✓ | ✓ |
| Share agents/prompts/folders with teams | ✓ | ✓ | ✓ | ✓ |
| Manage members and roles | ✓ | ✓ | ||
| Configure workspace models and KH | ✓ | ✓ | ||
| Manage billing, plan, and invoices | ✓* | ✓ | ✓ | |
| Delete the workspace | ✓ |
*Owners and the Billing role manage billing. Admins can manage the rest of the workspace configuration.
Sharing & Teams
Most resources can be shared with individual users, with teams, or with the whole workspace:
- Agents — share with users, teams, or the workspace; public, no-auth agent pages can be shared via link.
- Workflows — share with users and teams.
- Knowledge folders — share folders across the workspace; a sharing disclaimer can be configured by admins.
- Projects — share with individual users and teams.
- Prompts — share with the workspace.
Recommended Setup
For most organizations, we recommend:
- Keep Members empowered — let everyone create agents, upload documents, and share within their teams so people can build use cases quickly.
- Reserve Admin for a small group — model configuration, Knowledge Hub settings, and member management are powerful; keep them with a trusted few.
- Assign Billing intentionally — give the Billing role only to those who manage the plan and invoices.
You can change a member's role at any time in member settings.