Roles & Permissions
With teams sharing an organization, not everyone should be able to rename the org, remove members, or delete an agent. Members now have roles, and Nairi enforces them.
The two roles
- Admin — full access. Can invite and remove members, rename the organization, manage agents, secrets, rules, skills, and integrations, and view the activity history.
- Member — can use the org's agents and run jobs, but can't change org settings, manage members, delete agents, or touch secrets.
How roles are assigned
- Whoever creates an organization is its first admin.
- People who join by invite come in as members. An admin can rely on that: an invited teammate can't accidentally reconfigure the fleet.
- Everyone already in an organization before this shipped stays an admin, so nothing you could do yesterday is off-limits today.
Enforcement is always on. If a member tries an admin-only action, Nairi declines it with a clear reason rather than half-doing it.