Enterprise / Access control
Roles & Permissions
Roles decide what a member can do inside your organization. Pick a role to see the access it grants before you assign it.
Comparison
Compare the built-in roles
Roles are ordered from most to least privileged. A higher role includes what the roles below it can do.
- Can do
- Build with the platform: API keys, projects, and memory data.
- Give it to
- Engineers integrating MemorySync.
Beyond the defaults
Custom roles and least privilege
- Custom roles
- When the built-in set does not fit, define a role with exactly the permissions a job needs.
- Start low
- Assign the least privileged role that lets someone do their work, then raise it if they hit a wall. The reverse is harder to notice.
- Separate humans from services
- People get roles; integrations get API keys. Do not share one credential across both.
- Review periodically
- Use the member list and the audit trail to check that elevated roles are still justified.
Was this page helpful?