---
title: "Account roles and permissions"
canonical: https://workspace.socra.com/docs/admin/concepts/roles-and-permissions
---

# Account roles and permissions

Your Account role controls which resources you can see and change in Admin. The service that owns a resource makes the final authorization decision.

## Roles

An Account member has one role: owner, admin, member, or guest.

- **Owner:** Manages the Account, invitations, product access, billing, and domains.
- **Admin:** Manages permitted directory and group resources.
- **Member:** Uses available products and can participate in permitted groups.
- **Guest:** Has limited Account access.

## Owner-only areas

Admin reserves these areas for Account owners:

- [Pending invitations](/docs/admin/guides/manage-people)
- [Product access, seat assignment, and buying access](/docs/admin/guides/manage-product-access)
- [Billing overview, subscriptions, payment methods, usage, and invoices](/docs/admin/guides/manage-billing)
- [Changes to the Account image, name, and handle](/docs/admin/guides/manage-account)
- [Account deletion](/docs/admin/guides/manage-account#delete-an-account)

Owners also [create and verify domains](/docs/admin/guides/manage-domains). Other roles can review domains when their service permissions allow it.

## Group management

The Account owner, an Account admin, or the owner of a group can [edit that group and manage its members](/docs/admin/guides/manage-groups). A group owner cannot be removed from the membership list. Removing another member removes access granted through that group.

## Permission failures

Admin removes owner-only destinations from navigation for other roles. Direct links are also checked. If your role cannot open a destination, Admin returns you to **Home** and identifies the blocked task.
