Skip to content
Open the dashboard
Reference

Roles and permissions

Every member of a workspace has one role. This page lists every action in Groundrule and which roles can take it. The same rules apply in the dashboard, the API, and the CLI, and they are also enforced in the database.

To give someone a role, see Members and roles.

Role Description in the dashboard
Admin Everything, including members and invitations
Platform admin Workspace settings, teams, repositories, and rules
Standard owner Writes and adopts rules
Security reviewer Reads everything; review workflows are coming
Manager Reads everything
Developer Reads the rulebook and connects the CLI
Viewer Read-only

The roles fall into three groups:

  • Admins: admin only. They manage people and AI settings.
  • Workspace admins: admin and platform admin. They manage packs, teams, repositories, owners, connections and workspace settings.
  • Authors: admin, platform admin and standard owner. They write and adopt rules, decide on proposals, use AI and import documents.

Security reviewer, manager, developer and viewer have identical permissions today. Review workflows for security reviewers are not built yet.

✓ means the role can take the action. In the column headers: A admin, PA platform admin, SO standard owner, SR security reviewer, M manager, D developer, V viewer.

Action A PA SO SR M D V
See the dashboard, standards, rule details and versions ✓ ✓ ✓ ✓ ✓ ✓ ✓
See the catalog and packs ✓ ✓ ✓ ✓ ✓ ✓ ✓
See evidence, repositories and scans ✓ ✓ ✓ ✓ ✓ ✓ ✓
See the inbox, promotions and imported documents ✓ ✓ ✓ ✓ ✓ ✓ ✓
See teams, repositories and category owners ✓ ✓ ✓ ✓ ✓ ✓ ✓
See the member list ✓ ✓ ✓ ✓ ✓ ✓ ✓
See workspace settings and AI settings and usage ✓ ✓ ✓ ✓ ✓ ✓ ✓
See pending invitations and the allowed invitation domains ✓
See connected apps and GitHub installations ✓ ✓ ✓
See everyone’s API tokens (others see only their own) ✓ ✓
Action A PA SO SR M D V
Rename the workspace; change company, stack and coding agents ✓ ✓
Limit invitations to email domains ✓
Invite people; resend and revoke invitations ✓
Change a member’s role ✓
Remove a member ✓
Leave the workspace (unless you’re the last admin) ✓ ✓ ✓ ✓ ✓ ✓ ✓

Anyone signed in can create a new workspace, and becomes its admin.

Action A PA SO SR M D V
Turn packs on and off ✓ ✓
Mark a new pack version as reviewed ✓ ✓
Create and edit standards; test a check in the editor ✓ ✓ ✓
Publish a draft standard ✓ ✓ ✓
Turn a rule on or off; change its stage, severity or wording, at any scope ✓ ✓ ✓
Change many rules at once ✓ ✓ ✓
Promote a rule to its next stage, or hide a promotion ✓ ✓ ✓
Action A PA SO SR M D V
Create and delete teams; choose a team’s members ✓ ✓
Register, reassign and remove repositories ✓ ✓
Assign category owners ✓ ✓
Action A PA SO SR M D V
Accept, reject or reopen instruction and tool-setting proposals, one at a time or in bulk ✓ ✓ ✓
Accept, reject or reopen ownership proposals ✓ ✓
Import a document: upload, paste, or from a connected app ✓ ✓ ✓
Import pull-request reviews ✓ ✓ ✓
Refine with AI on imported agent-file instructions ✓ ✓ ✓
Start or cancel a document import ✓ ✓ ✓
Action A PA SO SR M D V
Turn AI on or off; set the budget and data retention ✓
Describe a rule and Draft with AI (when AI is on) ✓ ✓ ✓
Action A PA SO SR M D V
Connect and disconnect Notion, Google Docs and Confluence ✓ ✓
Install and disconnect the GitHub App ✓ ✓
Search connected apps and list GitHub repositories, to import ✓ ✓ ✓
Action A PA SO SR M D V
Approve groundrule login for this workspace ✓ ✓ ✓ ✓ ✓ ✓ ✓
Create API tokens for yourself ✓ ✓ ✓ ✓ ✓ ✓ ✓
Revoke your own tokens ✓ ✓ ✓ ✓ ✓ ✓ ✓
Revoke anyone’s tokens ✓ ✓
Read the rulebook with the CLI (sync, check) ✓ ✓ ✓ ✓ ✓ ✓ ✓
Upload scans (scan --upload) ✓ ✓ ✓ ✓ ✓ ✓ ✓
Propose rules from the CLI or a coding agent (propose, mcp) ✓ ✓ ✓ ✓ ✓ ✓ ✓

A token acts as the person who created it, with the permissions chosen for it: reading the rulebook always, and uploading scans and proposing rules if allowed. No token can do anything in the tables above other than these three things, whatever its owner’s role. See API tokens.

Rules proposed with /groundrule rule in a GitHub review comment don’t depend on a Groundrule role. Anyone who can comment on a pull request in a repository the GitHub App is installed on can send one; it arrives in the inbox as a proposal credited to their GitHub login, and an author decides on it. See Rules from pull-request reviews.

  • Most controls a role can’t use are hidden. For example, a developer sees the inbox without Accept or Reject, and settings panels show “Only admins and platform admins can change this.” or “Only admins can change AI settings.”
  • If an action is attempted anyway, Groundrule refuses it with a message naming the role and the action, such as “Your role (developer) can’t decide on proposals. Ask an admin.”
  • Someone who isn’t a member of a workspace gets “not found” for its URL, never “forbidden”, so workspace names aren’t revealed.
  • A workspace always has at least one admin. Changing the last admin’s role, removing them, or the last admin leaving is refused: “A workspace needs at least one admin. Make someone else an admin first.”
  • Admins can’t remove themselves from Members; they use Leave workspace instead.
  • Removing a member, or a member leaving, stops their API tokens from working at once.