Skip to main content
🚨Early AccessYour AI Team Just Got Smarter. Unlock Opus 5.5, Fable 5.1 & Sonnet 5.5, GPT-6 Astra GPT-6/6.1 Sol & GPT-6 Luna, Gemini 4 Argon with Team or Business.
Help Center / Roles & Permissions / Understanding roles: Organization, Workspace, Session
Roles & Permissions

Understanding roles: Organization, Workspace, Session

Updated Β· 4 min read

Orvoq has three separate levels of role, and holding a role at one level says nothing about your access at another. This trips people up more than anything else in the product, so it's worth being precise about.

Organization roles

RoleCan do
OwnerEverything an Admin can, plus billing, plan changes, deleting the org
AdminCreate workspaces, invite/remove org members, assign workspace roles
MemberExists in the org directory only β€” no access to anything until assigned to a workspace

Workspace roles

RoleCan do
OwnerManage Knowledge, Files, Agents, Models, and policies; invite/remove members
EditorCreate sessions, use enabled agents and models
ViewerRead-only access

Session roles

RoleCan do
OwnerInvite/remove participants, manage AI participants, archive or delete the session
EditorConverse, edit artifacts, create tasks, comment
ViewerRead-only, can comment if allowed
GuestSession-only, time-boxed β€” no workspace or org access implied
⚠ The one people miss most: a Workspace Viewer is not automatically a Viewer on every session in that workspace, and a Session Guest is never a workspace member, no matter how they joined. These are genuinely independent β€” check both if something seems locked.

Where AI fits in

Models and agents don't hold any of these roles. Instead, they're granted specific capabilitiesβ€” read a document, search the web, send a message β€” visible on each agent's profile. There's no such thing as making an AI agent an β€œOwner.”

β€œNo workspace access yet” is normal

If someone's listed in your organization but greyed out with no workspace shown, that's not an error β€” it's someone who was added to the org directory without being assigned anywhere yet. Assign them to a workspace whenever it's actually needed.

Was this article helpful?