Skip to main content
Reference

Organization role permissions reference

Compare Owner, Admin, Member, and Viewer permissions for organization access, invitations, billing, and shared Joule sessions.

Last verified 1 day ago

Use this reference when you need to compare what each organization role controls in Ampere. Organization roles affect team management and broad workspace access; billing admin access, Scheduled Task execution ownership, and shared Joule session roles use separate controls.

The current organization roles are Owner, Admin, Member, and Viewer.

Monitoring is an organization workspace surface where authorized members can review monitors and alerts.

Organization role matrix

Permission areaOwnerAdminMemberViewer
Belong to the organization workspaceYesYesYesYes
Invite teammates as Admin, Member, or ViewerYesYesNoNo
Change regular member rolesYesYesNoNo
Remove non-owner membersYesYesNoNo
Transfer organization ownershipYesNoNoNo
Update organization profile detailsYesYesNoNo
Receive billing access from the organization role itselfYesNoNoNo
Receive billing admin access through a separate billing settingAlready includedSeparate settingSeparate settingSeparate setting
See organization Scheduled Tasks and their basic status and scheduleYesYesYesYes
See private Scheduled Task inputs and run outputIf execution ownerIf execution ownerIf execution ownerIf execution owner
Govern a Scheduled Task owned by someone elseYesYesNoNo
See organization monitors and alertsYesYesYesYes
Mark a monitoring alert read or unread for yourselfYesYesYesYes
Resolve or reopen a shared monitoring alertYesYesYesYes
Be granted view, edit, or owner access on shared Joule sessionsYesYesYesView only

What admins and owners can manage

Admins and owners can open Settings and then Team to manage organization members and invitations. They can invite teammates as Admin, Member, or Viewer, update regular member roles, and remove non-owner members.

Owner changes use a dedicated ownership-transfer flow. Do not treat Owner as a normal invitation or role-dropdown choice. A person must already be a member of the organization before ownership can be transferred to them.

For Scheduled Tasks, owners and admins have governance controls even when another member is the execution owner. Current controls can include pausing an active task, canceling a run, managing email recipients, deleting the task, or taking it over. Governance access does not automatically reveal the execution owner's private task inputs, connections, Joule sessions, or run output.

Taking over changes the execution owner. It cancels runs in progress, removes the previous owner's attachments, connections, and approvals, and leaves the task paused for review. The new owner can edit the current setup but does not gain access to the previous owner's past private run results.

What members and viewers can do

Member is the standard role for teammates who work in the organization but do not need to manage team access.

Viewer is the lightest general organization role. Viewer access is useful when someone needs a narrower view of organization work. For shared Joule sessions, viewers can only receive view access.

Most shared work in Ampere belongs to an organization. That includes projects, uploaded files, AI Tool executions, Scheduled Tasks, monitors and alerts, AI avatars, custom voices, billing, usage, and connected accounts. Some records also track the person who created or executes the work, so organization-wide visibility does not mean every teammate can open every private input or output.

Scheduled Task visibility and execution ownership are separate

Organization members can see the Scheduled Tasks list and basic details such as a task's name, type, status, schedule, and run counts. The task's Created by and Execution owner fields explain who created it and whose private execution context it uses.

The execution owner can inspect and edit private inputs, run the task, resolve approvals, and open private run output. Those capabilities come from execution ownership rather than the person's organization role. A workspace owner or admin can govern or take over another person's task, but cannot inspect its private execution details before taking it over.

This boundary also applies when a person's organization role changes. Use the task's available actions and ownership fields as the current source of truth instead of assuming that Admin or Owner automatically grants private execution access.

Monitoring alerts have personal and shared state

Organization members can review monitors, alerts, and the evidence attached to an alert. Monitoring uses two different kinds of state:

  • Read and unread are personal. Marking an alert read clears it for you; it does not clear another teammate's unread count.
  • Open and resolved are shared. Resolving or reopening an alert changes the lifecycle for the organization and can show who resolved it and when.

All current organization roles can use the read/unread and resolve/reopen actions. These alert-review actions are separate from the admin-only controls used to manage teammates and organization settings.

Monitor follow-up sessions keep their own access

A monitor can start a Joule follow-up after it finds a change. The alert remains visible to organization members, but the linked Joule session follows its own session access rules.

If you have access to that session, the alert can show the follow-up output and provide a link to open it. If you do not, Ampere shows the follow-up as restricted. Being an organization owner or admin does not by itself grant access to another person's private Joule follow-up session.

Shared Joule sessions use session-specific roles: no access, view, edit, and owner. Owners, admins, and members can be granted view, edit, or owner access. Viewers can receive view access only.

Billing access is separate

Organization roles and billing administration are not the same setting. Owners have billing access automatically. Other teammates can be granted billing admin access separately, so finance or operations teammates can help manage billing without becoming organization owners.

Use Team settings for organization roles. Use billing pages when you need to manage plans, credits, top-ups, auto-recharge, invoices, payment methods, usage, or billing admin access.

Choose the least powerful role that fits

Start with the least powerful role that still lets the teammate do their job. Use Admin when someone needs to manage team access, organization settings, or organization-level Scheduled Task governance. Use Member or Viewer when they do not need those controls.

Then review resource-specific access separately. Confirm the execution owner for Scheduled Tasks, the read or resolution state for monitoring alerts, the session role for shared Joule work, and billing admin access for billing tasks.

Was this article helpful?

Related articles