Skip to main content
🚨Early AccessOrvoq is currently in early access. Expect occasional rough edges as we test, refine, and prepare for launch.
Help Center / Roles & Permissions / Understanding roles: Organization, Workspace, Session
Roles & Permissions

Understanding roles: Organization, Workspace, Session

Updated August 2026 Β· 4 min read

Orvoq has three separate levels of role, and holding a role at one level says nothing about your access at another. This trips people up more than anything else in the product, so it's worth being precise about.

Organization roles

RoleCan do
OwnerEverything an Admin can, plus billing, plan changes, deleting the org
AdminCreate workspaces, invite/remove org members, assign workspace roles
MemberExists in the org directory only β€” no access to anything until assigned to a workspace

Workspace roles

RoleCan do
OwnerManage Knowledge, Files, Agents, Models, and policies; invite/remove members
EditorCreate sessions, use enabled agents and models
ViewerRead-only access

Session roles

RoleCan do
OwnerInvite/remove participants, manage AI participants, archive or delete the session
EditorConverse, edit artifacts, create tasks, comment
ViewerRead-only, can comment if allowed
GuestSession-only, time-boxed β€” no workspace or org access implied
⚠ The one people miss most: a Workspace Viewer is not automatically a Viewer on every session in that workspace, and a Session Guest is never a workspace member, no matter how they joined. These are genuinely independent β€” check both if something seems locked.

Where AI fits in

Models and agents don't hold any of these roles. Instead, they're granted specific capabilitiesβ€” read a document, search the web, send a message β€” visible on each agent's profile. There's no such thing as making an AI agent an β€œOwner.”

β€œNo workspace access yet” is normal

If someone's listed in your organization but greyed out with no workspace shown, that's not an error β€” it's someone who was added to the org directory without being assigned anywhere yet. Assign them to a workspace whenever it's actually needed.

Was this article helpful?