> ## Documentation Index
> Fetch the complete documentation index at: https://help.alk.work/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding Roles & Access

> How role-based access control works in ALK, at both the organisation (Entity) and Workspace level.

### Overview

This article explains how access control works in ALK — what roles exist, what each role can and can't do, and how workspace-level access builds on top of your organisation-level role. Read this before inviting team members or setting up workspaces for your organisation.

### How Access Works

ALK manages access at two levels: your organisation (called an Entity) and individual Workspaces within it. Your organisation-level role applies across everything, while your workspace role controls what you can do inside a specific workspace.

Think of it this way: your entity role is your company-wide clearance, and your workspace role is which rooms you're allowed into.

### Organisation-level Roles

To view more information about your organisation-level role permissions, visit settings > team > role.

There are four roles at the organisation level:

* **Owner** has full control of the organisation. Best suited for founders or the primary account holder. Only the Owner can delete workspaces.
* **Admin** has same permissions as Owner, except Admins cannot remove Owners. Best for IT leads and team managers responsible for inviting users and managing the platform.
* **Members** are day-to-day contributors. Members can upload files, edit, organise, and save insights, but cannot invite or remove users or manage integrations.
* **Viewers** have read-only access. Viewers can only see content they've been given access to. No uploads, edits, or configuration changes.

### Workspace-level Roles

Within each workspace, members have one of two roles:

* **Workspace Admin (ws\_admin)**: Can manage workspace members, assign roles within that workspace, and connect or disconnect integrations. Cannot delete the workspace, only the Entity Owner can do that.
* **Workspace Member (ws\_member)**: Full participation in the workspace: can add, view, and delete files, and create or view conversations. Cannot manage members or integrations.

### What Each Role Can Do (quick reference)

| Action                      | Owner | Admin | Ws Admin | Ws Member |
| --------------------------- | ----- | ----- | -------- | --------- |
| Create workspaces           | ✓     | ✓     | ✗        | ✗         |
| Delete workspaces           | ✓     | ✗     | ✗        | ✗         |
| Invite users to workspace   | ✓     | ✓     | ✓        | ✗         |
| Assign workspace roles      | ✓     | ✓     | ✓        | ✗         |
| Connect integrations        | ✓     | ✓     | ✓        | ✗         |
| Add / view / delete files   | ✓     | ✓     | ✓        | ✓         |
| Create / view conversations | ✓     | ✓     | ✓        | ✓         |

**A few things to know**

* The first person to sign up for your organisation automatically becomes the Owner. Choose this account carefully, it carries the highest level of access and is the only role that can delete workspaces.
* Entity Owners have implicit access to every workspace in the organisation, even if they haven't been explicitly added to it.
* A user can only hold one organisation-level role at a time. If someone needs broader access, their role needs to be updated, not supplemented.

## Related articles

* [Setting Up Your Workspace](/admin/setting-up-your-workspace)
* [Inviting & Managing Team Members](/admin/inviting-managing-team-members)
* [Managing Integrations](/integrations/managing-integrations)

## Need help?

If you run into issues, contact the Wamiri support team at [support@wamiri.com](mailto:support@wamiri.com). Include a description of the issue, any error messages you're seeing, and the steps you've already tried.
