For the complete documentation index, see llms.txt. This page is also available as Markdown.

Access and Permissions

Manage and invite team members

Permissions on AirOps

AirOps offers five roles, each scoped to what a teammate needs to do:

  • Admin: Full, unrestricted workspace control, including members, billing, and workspace settings.

  • Developer: Build and run Actions, manage integrations and secrets. Views Brand Kits.

  • Brand Manager: Manage Brand Kits and Knowledge Bases. Can run and view Workflows and Playbooks, but cannot edit them.

  • Member: Build and run Actions, edit Grids and Knowledge Bases. Views Brand Kits.

  • Guest: Grid-only access for contractors and reviewers, with no other workspace access.

What each role can do

The table below summarizes access by area. Full means view and edit, View only means read access without editing, and a dash means no access.

Capability
Admin
Developer
Brand Manager
Member
Guest

Content & building

Workflows

Full

Full

View only

Full

-

Playbooks

Full

Full

View only

Full

-

Grids

Full

Full

Full

Full

Full

Run Actions

Full

Full

Full

Full

-

Prompts & Analytics

Full

Full

Full

View only

-

Brand context

Brand Kits

Full

View only

Full

View only

-

Knowledge Bases

Full

Full

Full

Full

-

Integrations

Integration configuration

Full

Full

View only

View only

-

Secrets & API keys

Full

Full

-

-

-

Workspace management

Team management

Full

View only

View only

View only

-

Usage & billing

Full

View only

View only

View only

-

SSO configuration

Full

-

-

-

-

These permissions are enforced everywhere, not just in the web app. The same role-based access applies through Quill and MCP.

Which roles are available on my plan?

The roles you can assign depend on your workspace plan. Higher plans unlock more granular roles.

Plan
Available roles

Solo

Admin

Pro

Admin, Member

Enterprise

Admin, Developer, Brand Manager, Member, Guest

Custom Roles

Enterprise workspaces can build roles from scratch when the five fixed roles don't fit. A custom role grants access area by area, using the same capability areas as the table above.

To build one, go to Settings → Roles and select Create role, then name it and set access for each area:

  • No access

  • View only

  • View & run: available on Workflows and Playbooks only.

  • Full: not available for Team management, which always requires Admin.

Once created, a custom role is enforced the same way as fixed roles, including through Quill and MCP.

How do I invite new team members?

Navigate to ⚙️ Settings → Team to manage existing and invited users within your Workspace. When inviting a teammate, choose the role that matches what they need to do. The invite dialog shows a summary of each role's access as you select it.

Last updated

Was this helpful?