Roles & Access
Manage organization roles, permissions and access policies synced with Logto.
Total roles
6
Synced from Logto
System roles
6
Protected roles
Privileged users
3
Owner/Admin access
Access policies
3
Active controls
Last sync
Now
Logto connected
Role definitions
Roles available in this organization. System roles are synced from Logto and policy metadata is stored in Directus.
Owner
Full ownership of workspace, billing, members and security settings.
Members
1
Scope
Organization
Admin
Administrative access to members, roles, apps and security settings.
Members
2
Scope
Organization
Billing Admin
Manage billing profile, invoices, payment methods and subscriptions.
Members
1
Scope
Billing
App Admin
Configure application access, requests and provisioning settings.
Members
3
Scope
Applications
Member
Standard workspace access to assigned applications.
Members
32
Scope
Workspace
Viewer
Read-only access to workspace resources and audit visibility.
Members
3
Scope
Workspace
Permission matrix
Effective administrative access by role.
| Permission | Owner | Admin | Billing Admin | App Admin | Member | Viewer |
|---|---|---|---|---|---|---|
| Manage members | Full | Full | Denied | Limited | Denied | Denied |
| Manage roles | Full | Full | Denied | Denied | Denied | Denied |
| Manage billing | Full | Limited | Full | Denied | Denied | Read only |
| Manage applications | Full | Full | Read only | Full | Limited | Read only |
| View audit logs | Full | Full | Limited | Limited | Denied | Read only |
| Manage security | Full | Full | Denied | Limited | Denied | Read only |
| Manage organization profile | Full | Full | Limited | Limited | Read only | Read only |
Access policies
Controls that apply to privileged and administrative roles.
Require MFA for admins
Owner, Admin and Billing Admin must use multi-factor authentication.
Restrict billing access
Only Owner and Billing Admin can manage billing settings.
Review privileged roles
Admin and Owner assignments should be reviewed every billing cycle.