Access rights model (RBAC)
Levels: Account / Workspace
Section titled “Levels: Account / Workspace”Access rights in Contradic work at two levels. An account role controls account-wide responsibilities and can also provide access across workspaces. A workspace role controls what a member can do in one workspace.
Where you manage each level:
- Account membership lives in Account Settings on the Team tab, where the account owner invites people and sets their account role.
- Workspace access lives in Workspace settings on the Members tab. This tab is available to workspace administrators.
Common entry points:
- Open the account menu (your avatar in the sidebar) with and choose Account Settings to manage account-level access.
- Open a workspace, choose Workspace settings, then select Members to grant, change, or revoke workspace access.
Account Owners and Admins automatically have administration access to every workspace in their account. They do not need a separate workspace grant. Account Collaborators and Guests must be added to each workspace they need to use.
If you are new to the difference between accounts and workspaces, see Understand accounts and workspaces.
Roles: Owner, Admin, Collaborator, Guest
Section titled “Roles: Owner, Admin, Collaborator, Guest”Every member has an account role. Members who do not inherit workspace access can also have a role in each workspace they are allowed to use.
Account role overview:
- Owner: Controls the account, including member removal and billing, and automatically administers every workspace.
- Admin: Can invite members, manage account roles, and automatically administer every workspace.
- Collaborator: Has no workspace access until a workspace administrator grants it. Their workspace role can be Guest, Collaborator, or Admin.
- Guest: Has no workspace access until it is granted and can only receive Guest access.
Inside a workspace:
- Owner identifies the workspace creator. Their workspace access cannot be changed or revoked from Workspace settings while their account membership is active.
- Admin can manage workspace settings and member access, as well as create and edit documents, notes, and views.
- Collaborator can create and edit documents, notes, and views, and run AI Experts for guided analysis.
- Guest can view documents, notes, and views but cannot change them.
Tip: Give Guest access to someone who only needs to review information, Collaborator access to someone who contributes content, and Admin access only to someone who manages the workspace.
To learn how invitations and role changes work, jump to the full guide:
Invite and manage collaborators
Permissions table
Section titled “Permissions table”Use this table as a quick reference for how the account role determines workspace access.
| Account role | Default access to account workspaces | Workspace assignment |
|---|---|---|
| Owner | Administrator access to every workspace | No separate grant is required; inherited access cannot be lowered in Workspace settings |
| Admin | Administrator access to every workspace | No separate grant is required; inherited access cannot be lowered in Workspace settings |
| Collaborator | No access until granted | Can be assigned Guest, Collaborator, or Admin in each workspace |
| Guest | No access until granted | Can only use Guest access in each workspace |
Removing someone from the account ends all of their access to its workspaces, including any explicit workspace grants. Removing only a workspace grant does not remove their account membership or access to other workspaces.
Need a quick reminder on invitations? See Invite and manage collaborators.