Roles & Permissions
Team roles
Section titled “Team roles”These are the roles you assign to people on your team. They control what a person can do inside your organization.
| Role | Description |
|---|---|
| Owner | Full control. Manages billing, can delete the org, toggles Member governance, assigns all roles. |
| Admin | Manages and deletes all agents, integrations, knowledge, flows, skills and team members; approves pending items. No billing. |
| Member | Creates agents, integrations, knowledge, flows, skills and voices, and runs/edits agents. Cannot delete shared resources, manage billing, or invite members. What a member can do with each agent is set per agent — see Agent access. |
| Guest | Read-only, invite-based collaborator. Views a specific invited agent/run, but cannot make changes. Access is granted by invitation and can be revoked at any time — see Guest access below. |
System roles
Section titled “System roles”You don’t assign these — Auteryn manages them automatically. They exist so that non-team identities (your end-users and the agents themselves) can be represented in the platform.
| Role | Description |
|---|---|
| Customer | An end-user who interacts with one of your customer-facing agents (via the web widget, Telegram, WhatsApp, and other channels). Customers are not members of your organization and have no Console access — they only ever converse with the agent you expose to them. |
| Agent | The agent’s own identity within the organization. This role represents actions taken by an agent (for example, when an agent runs a flow or writes back to a connected integration) rather than by a person. It is assigned by the platform and cannot be granted to a user. |
Role capabilities
Section titled “Role capabilities”| Action | Owner | Admin | Member | Guest |
|---|---|---|---|---|
| Create agents / knowledge / flows / skills / voices | ✅ | ✅ | ✅ | ❌ |
| Run & edit agents | ✅ | ✅ | per agent access | ❌ |
| Connect integrations | ✅ | ✅ | ✅¹ | ❌ |
| Delete agents / integrations / knowledge / skills / voices / flows | ✅ | ✅ | ❌ | ❌ |
| Approve pending items (governance) | ✅ | ✅ | ❌ | ❌ |
| Invite / remove members, change roles | ✅ | ✅ | ❌ | ❌ |
| Create / revoke API keys | ✅ | ✅ | agent/customer keys only² | ❌ |
| Manage org settings & branding | ✅ | ✅ | ❌ | ❌ |
| View billing | ✅ | ❌ | ❌ | ❌ |
| Delete the organization | ✅ | ❌ | ❌ | ❌ |
¹ With Member governance on, a member’s new resource stays pending approval until an owner or admin approves it. See Member governance.
² Members can create org API keys scoped to the agent or customer role (for running agents or authenticating end-users). Only owners and admins can create member-scoped keys or revoke keys they don’t own.
Inviting a team member
Section titled “Inviting a team member”- Go to Settings → Team
- Click Invite Member
- Enter their email and select a role
- Click Send Invite
Changing a member’s role
Section titled “Changing a member’s role”- Go to Settings → Team
- Click the role dropdown next to their name
- Select the new role
Admins cannot promote someone to Owner.
Removing a member
Section titled “Removing a member”Settings → Team → [member] → Remove from organization
Removed members immediately lose all access to the org. Removing a member also revokes their personal connections, deletes the own-account connections they added under “acts as each user” agents, transfers any shared or service connections they owned to an admin, pauses the automations they created (goals, loops, flows), and wipes any of their credentials from agent computers — so nothing keeps acting as a departed person.
Guest access
Section titled “Guest access”A guest is a read-only collaborator you invite to a single agent or run — useful for sharing an agent’s output with a stakeholder or client who shouldn’t join your organization. Guests can view what you invite them to, but cannot run, edit, or delete anything.
Invite a guest
- Open the agent (or run) you want to share
- Choose Share → Invite guest
- Enter their email and send the invite
Accept
The guest opens the invitation link from their email and signs in. Their access is scoped to only the agent/run you shared — nothing else in your organization is visible to them.
Revoke
Guest access has an active/revoked lifecycle. To revoke, open the shared agent’s guest list and choose Revoke next to the guest. Revocation takes effect immediately, and the guest loses access to the shared agent/run.

