Roles & Permissions
Roles & Permissions
What a user can do in your organization is managed differently depending on your plan:
- On the Starter and Business plans, every user has one of two roles: Administrator or Writer.
- On the Enterprise plan, there are no roles to assign. Access comes from groups: each group carries a set of fine-grained permissions, and a user can do whatever their groups allow.
Roles (Starter and Business plans)
Writer is the default. Everyone who joins your organization starts as a Writer.
Change a user’s role
In the console, go to Settings → Team Management → Users and use the role selector next to a person to set them as Administrator or Writer. See Users.
Role changes take effect immediately. An organization always keeps at least one Administrator — Markup AI blocks any change that would remove the last one.
Fine-grained permissions (Enterprise plan)
On the Enterprise plan, the two fixed roles are replaced by groups. There’s no role selector: instead, you define groups and choose exactly what each group’s members can do from a permissions grid — switches organized by area, such as style guides and terminology, the Brand Profile, and organization management. This is how you give a documentation team the ability to maintain Brand Profile, for example, without giving its members every administrative permission.
Every organization starts with two built-in groups that mirror the roles above — Writers, which everyone joins automatically, and Administrators, whose members can manage the whole workspace. You can use just those two, or add your own groups alongside them.
A user’s effective access is the sum of:
- your organization’s default permissions — what every member can do regardless of groups, plus
- the permissions granted by every group they belong to.
Access is positive-only: there are no “deny” rules. To broaden someone’s access, add them to a group or switch on a permission; to narrow it, remove one. This keeps the model predictable — you can always answer “why can this person do that?” by looking at their groups.
Two guardrails to know about:
- The Administrators group is protected. Any change that would leave the organization without an administrator is blocked.
- You can only grant what you hold. Adding someone to a group — or mapping an identity-provider group to it — requires that you yourself hold every permission that group grants. Nobody can hand out access they don’t have.
Fine-grained permissions and groups are available on the Enterprise plan — talk to your account team to enable them. Changes to a user’s permissions or group membership take effect on their next sign-in.