Roles & Access
Roles & Access
Access in AI Red Teaming is controlled by two independent layers: a role in your organization, and a role in each folder. They do not inherit from each other — an organization member’s power over a folder comes from their folder role, with one exception: organization admins act as admin on every folder in their organization.
Organization roles
- Admin — sees and manages all folders and content in the organization, effectively holding the admin role on every folder. Admins also manage the organization’s members and their roles.
- Member — sees only the folders they belong to. What they can do there is determined by their folder role.
Folder roles
Each folder member holds one of three roles: Viewer, Member, or Admin. Every capability below was verified against the platform’s authorization rules.
Additional rules:
- Moving content requires rights on both ends: permission to move the item out of its source folder (own content needs Member, others’ content needs Admin) and the Member role or higher in the destination folder.
- A folder always keeps at least one admin — the last admin cannot be removed or demoted.
- The built-in folders are restricted: your personal folder cannot be shared, renamed, or deleted, and the organization folder (Everyone at {your organization}) cannot be renamed or deleted.
How access is assigned
Folder roles
Folder roles are managed per folder, by that folder’s Admins:
- Whoever creates a folder becomes its Admin.
- Folder Admins add organization members and set their roles in the folder’s settings — the gear icon in the folder dropdown on the Targets, Evaluations, or Scans pages (the dialog it opens also links to the full Manage folders page), or Settings → Manage folders → Members. Only members of your organization can be added.
- Everyone in the organization is automatically a Member of the organization folder.
Organization roles
- Organization admins assign organization roles under Settings → Org members: each member is either Admin or a regular member.
- A role change takes effect the next time the member signs in.
Organization admin is a broad permission — it grants admin-level access to every folder in the organization. Follow the principle of least privilege: keep day-to-day collaboration on folder roles, and reserve the organization Admin role for the few people who administer the workspace.