> ## Documentation Index
> Fetch the complete documentation index at: https://docs.gocromo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> Understand what Viewers, Members, Admins, and Owners can do in a Cromo Workspace and Project.

Cromo derives permissions from a person's role in the active Workspace. Access to Project-scoped content also requires membership in that Project.

Roles are cumulative: each role includes the capabilities of the role before it.

## Role summary

| Capability                                                | Viewer | Member | Admin | Owner |
| --------------------------------------------------------- | :----: | :----: | :---: | :---: |
| Use chat                                                  |    ✓   |    ✓   |   ✓   |   ✓   |
| Read Knowledge and Sources                                |    ✓   |    ✓   |   ✓   |   ✓   |
| Add, edit, review, or delete Sources and Knowledge        |        |    ✓   |   ✓   |   ✓   |
| Read Data, Dashboards, and Workflows                      |    ✓   |    ✓   |   ✓   |   ✓   |
| Create or change Data                                     |        |    ✓   |   ✓   |   ✓   |
| Create, publish, and run Dashboards                       |        |    ✓   |   ✓   |   ✓   |
| Delete Dashboards                                         |        |        |   ✓   |   ✓   |
| Create, approve, and run Skills or Workflows              |        |    ✓   |   ✓   |   ✓   |
| View connector configuration                              |    ✓   |    ✓   |   ✓   |   ✓   |
| Use approved connectors                                   |        |    ✓   |   ✓   |   ✓   |
| Manage connectors                                         |        |        |   ✓   |   ✓   |
| View members and settings                                 |    ✓   |    ✓   |   ✓   |   ✓   |
| Manage Project and Workspace members, roles, and settings |        |        |   ✓   |   ✓   |
| View billing                                              |    ✓   |    ✓   |   ✓   |   ✓   |
| Manage billing                                            |        |        |       |   ✓   |

## Viewer

Use Viewer for people who need to ask questions, inspect Project context, and monitor operations without changing shared assets.

A Viewer can:

* use the assistant;
* read Sources, Knowledge, Data, Dashboards, Workflows, connectors, members, settings, and billing information.

## Member

Use Member for regular contributors and operators.

In addition to Viewer access, a Member can:

* add, change, review, and delete Sources and Knowledge;
* create, update, and delete Data;
* create, publish, and execute Dashboards;
* create, execute, and approve Skills and Workflows;
* use approved connectors.

## Admin

Use Admin for people who manage access and configuration.

In addition to Member access, an Admin can:

* delete Dashboards;
* manage connectors;
* add or remove Project members;
* manage Project settings;
* manage Workspace members, roles, and settings.

Admins can view billing but cannot manage it.

## Owner

An Owner has every Cromo permission, including billing management.

Keep at least one active Owner in the Workspace. Limit the role to people who are responsible for the Workspace as a whole.

## Project membership

A Workspace role does not automatically grant access to every Project. The user must also be a member of the Project for Project-scoped permissions to apply.

An Admin or Owner can add an existing Workspace member to a Project. Removing a user from a Project does not remove their Workspace membership.

## Apply least privilege

* Use Viewer for read-only stakeholders.
* Use Member for everyday contributors.
* Use Admin only for people managing access, settings, or connector credentials.
* Use Owner only where billing and full Workspace control are required.
* Review membership when ownership or employment changes.
* Pause owner-dependent Workflows before removing their owner from a Project.
