Roles & Permissions

What a user can do in your organization is managed differently depending on your plan:

  • On the Starter and Business plans, every user has one of two roles: Administrator or Writer.
  • On the Enterprise plan, there are no roles to assign. Access comes from groups: each group carries a set of fine-grained permissions, and a user can do whatever their groups allow.

Roles (Starter and Business plans)

RoleWhat it can do
WriterUse Markup AI: check and improve content with the agents your organization has enabled. Writers can see the style guides, terminology, and Brand Profile the organization has set up, and see who else is in the workspace. They can’t change any configuration.
AdministratorEverything Writers can do, plus manage the workspace: invite and remove people and change their roles, configure style guides, terminology, and the Brand Profile, manage organization settings, API keys, and view reports.

Writer is the default. Everyone who joins your organization starts as a Writer.

Change a user’s role

In the console, go to Settings → Team Management → Users and use the role selector next to a person to set them as Administrator or Writer. See Users.

Role changes take effect immediately. An organization always keeps at least one Administrator — Markup AI blocks any change that would remove the last one.

Fine-grained permissions (Enterprise plan)

On the Enterprise plan, the two fixed roles are replaced by groups. There’s no role selector: instead, you define groups and choose exactly what each group’s members can do from a permissions grid — switches organized by area, such as style guides and terminology, the Brand Profile, and organization management. This is how you give a documentation team the ability to maintain Brand Profile, for example, without giving its members every administrative permission.

Every organization starts with two built-in groups that mirror the roles above — Writers, which everyone joins automatically, and Administrators, whose members can manage the whole workspace. You can use just those two, or add your own groups alongside them.

A user’s effective access is the sum of:

  • your organization’s default permissions — what every member can do regardless of groups, plus
  • the permissions granted by every group they belong to.

Access is positive-only: there are no “deny” rules. To broaden someone’s access, add them to a group or switch on a permission; to narrow it, remove one. This keeps the model predictable — you can always answer “why can this person do that?” by looking at their groups.

Two guardrails to know about:

  • The Administrators group is protected. Any change that would leave the organization without an administrator is blocked.
  • You can only grant what you hold. Adding someone to a group — or mapping an identity-provider group to it — requires that you yourself hold every permission that group grants. Nobody can hand out access they don’t have.

Fine-grained permissions and groups are available on the Enterprise plan — talk to your account team to enable them. Changes to a user’s permissions or group membership take effect on their next sign-in.