# Roles and Permissions

Viresso uses a role-based permission system. Each workspace member is assigned one of four roles, ordered from broadest to narrowest access: **Administrator**, **Editor**, **User**, or **Viewer**.

## Roles

| Role | Description |
|---|---|
| **Administrator** | Full access to all workspace resources and settings |
| **Editor** | Manages all content and the content model without workspace administration access |
| **User** | Can create and manage entries, files, and forms, but cannot change the content model or workspace configuration |
| **Viewer** | Read-only access to content |

## Administrator

Administrators have every permission within the workspace. They can:

- Create, update, and delete content buckets, content types, entries, and files
- Manage API keys, webhooks, pipelines, and notification settings
- Add, remove, and change member roles
- View invoices, audit logs, and request logs
- Delete the workspace

## Editor

Editors have every User permission and can also create, update, and delete content buckets and content types. They cannot manage workspace settings, members, API keys, webhooks, pipelines, invoices, or audit logs.

## User

Users can work with content but cannot change how the workspace is configured. They have:

| Resource | Permissions |
|---|---|
| Entries | Create, read, update, delete |
| Files | Create, read, update, delete |
| Forms | Create, read, update, delete |
| Content Buckets | Read only |
| Content Types | Read only |
| Workspace | Read only |
| API keys | No access |
| Webhooks | No access |
| Members | No access |
| Request logs | Read only |

## Viewer

Viewers have read-only access to entries, files, forms, content buckets, content types, and the workspace. They cannot create, update, or delete content and cannot access administrative resources or request logs.

## Permission reference

The following resources are controlled by permissions:

| Resource | Administrator | Editor | User | Viewer |
|---|---|---|---|---|
| Entries | Full CRUD | Full CRUD | Full CRUD | List, View |
| Files | Full CRUD | Full CRUD | Full CRUD | List, View |
| Forms | Full CRUD | Full CRUD | Full CRUD | List, View |
| Content Buckets | Full CRUD | Full CRUD | List, View | List, View |
| Content Types | Full CRUD | Full CRUD | List, View | List, View |
| API Keys | Full CRUD | — | — | — |
| Webhooks | Full CRUD | — | — | — |
| Pipelines | Full CRUD and execute | — | — | — |
| Workspace Users (members) | Add, Update, Remove | — | — | — |
| Workspace | Full CRUD | View | View | View |
| Workspace Settings | Manage | — | — | — |
| Invoices | List, View | — | — | — |
| Audit Logs | List, View | — | — | — |
| Request Logs | List, View | List, View | List, View | — |

## Related pages

- [Members and Access](/docs/platform/members-and-access) — Adding and managing team members.
- [Workspace Settings](/docs/platform/workspace-settings) — Configuring your workspace.
