Skip to content

Roles and permissions

Permissions in Telmoni are governed by three roles: Owner, Admin, and Member. Roles operate at two levels: across the Organization and within individual Projects.

Retired roles from earlier versions—such as editor, viewer, read_only, and developer—are unparseable and rejected.

An organization role governs workspace management: creating projects, managing organization settings, invite authority, and organization-wide audit logs.

Permission Owner Admin Member
View organization settings and projects Yes Yes No
Create new projects Yes Yes No
Delete projects Yes No No
Manage organization settings and rename Yes Yes No
Manage organization members and invites Yes Yes No
View rolled-up organization audit log Yes Yes No
Transfer organization ownership Yes No No
Delete organization (14-day restore window) Yes No No
  • Owner: Full access to the organization and all its projects. Can create and delete projects, manage settings, invite and remove members, view rolled-up audit logs, transfer ownership to an Admin, or delete the organization.
  • Admin: Administrative access across the organization. Can create projects, manage settings, invite members, view rolled-up audit logs, and acts with admin authority in every project. Cannot delete projects, transfer ownership, or delete the organization.
  • Member: Default role for invited members. Has no organization-wide management authority. Access is limited strictly to the projects they have been seated in, governed by their project role.

Inside each project, a project role decides what you can do with project resources: API tokens, connectors, and project audit events.

Permission Owner Admin Member
View project overview and resources Yes Yes Yes
View API keys (names and dates, never the raw key) Yes Yes Yes
Create, rotate, and revoke API keys Yes Yes No
View connectors and delivery logs Yes Yes Yes
Create, test, update, and disconnect connectors Yes Yes No
Rotate webhook secrets, resend deliveries Yes Yes No
View project members Yes Yes Yes
Invite members to project, change project roles Yes Yes No
Read project audit log Yes Yes No
Update project settings and rename Yes Yes No
Transfer project to another organization Yes No No
Delete project Yes No No
  • Owner: Full control over the project, including project deletion and transferring the project to another organization. The organization Owner holds Owner privileges across all projects in the organization.
  • Admin: Operates the project: creates, rotates, and revokes API keys; manages Slack, Discord, and webhook connectors; manages project seats; and reads the project audit log. Cannot delete or transfer the project.
  • Member: Read-only access to project resources. Can inspect active connectors, delivery logs, and API key metadata (name, creation date, last used date). Cannot view the project audit log and cannot mutate any resources.

When you attempt an action your role does not allow, the API and console refuse the request with a 403 Forbidden response and an /errors/authz/insufficient-role problem document. The detail field names the least role required to perform the action:

{
"type": "/errors/authz/insufficient-role",
"title": "insufficient role",
"status": 403,
"detail": "required admin, have member"
}

Permissions are verified on every request in the backend services against row-level security policies and database transaction locks.