Roles & Access

Access in AI Red Teaming is controlled by two independent layers: a role in your organization, and a role in each folder. They do not inherit from each other — an organization member’s power over a folder comes from their folder role, with one exception: organization admins act as admin on every folder in their organization.

Organization roles

  1. Admin — sees and manages all folders and content in the organization, effectively holding the admin role on every folder. Admins also manage the organization’s members and their roles.
  2. Member — sees only the folders they belong to. What they can do there is determined by their folder role.

Folder roles

Each folder member holds one of three roles: Viewer, Member, or Admin. Every capability below was verified against the platform’s authorization rules.

CapabilityViewerMemberAdmin
See folder content (targets, evaluations, scans)
Create content and run scans or evaluations
Edit, move, or delete own content
Edit, move, or delete others’ content
Create folder-scoped API keys
Revoke API keysown only
Rename the folder
Add or remove members, change roles
Delete the folder

Additional rules:

  1. Moving content requires rights on both ends: permission to move the item out of its source folder (own content needs Member, others’ content needs Admin) and the Member role or higher in the destination folder.
  2. A folder always keeps at least one admin — the last admin cannot be removed or demoted.
  3. The built-in folders are restricted: your personal folder cannot be shared, renamed, or deleted, and the organization folder (Everyone at {your organization}) cannot be renamed or deleted.

How access is assigned

Folder roles

Folder roles are managed per folder, by that folder’s Admins:

  1. Whoever creates a folder becomes its Admin.
  2. Folder Admins add organization members and set their roles in the folder’s settings — the gear icon in the folder dropdown on the Targets, Evaluations, or Scans pages (the dialog it opens also links to the full Manage folders page), or SettingsManage foldersMembers. Only members of your organization can be added.
  3. Everyone in the organization is automatically a Member of the organization folder.

Organization roles

  1. Organization admins assign organization roles under SettingsOrg members: each member is either Admin or a regular member.
  2. A role change takes effect the next time the member signs in.

Organization admin is a broad permission — it grants admin-level access to every folder in the organization. Follow the principle of least privilege: keep day-to-day collaboration on folder roles, and reserve the organization Admin role for the few people who administer the workspace.