Governance & access
Roles & permissions
Three roles. Every rule below is enforced on the server; the UI hiding a control is a convenience, not the boundary.
CapabilityOwnerAdminMember
Read workspace factsYesYesYes
Connect team sourcesYesYes—
Invite & manage membersYesYes—
See confidential factsYesYes—
Approve playbooksYesYes—
Merge entitiesYesYes—
Export or delete the workspaceYes——
