Roles and Permissions
Every member of an organization has exactly one role. The role decides what that member can see and do. Surplus enforces every role on the backend, so a member can only ever do what their role permits.
The roles at a glance
Hovering any role in the assign or invite dropdowns shows this summary inline.
What each role can and cannot do
Owner
Everything. An owner can manage members and roles, workspaces, keys, offers, wallets, billing, budgets, and payouts (including withdrawals), and can read all usage, finance, audit, and request-log data. An owner is the only role that can change or remove another owner, or grant the owner role.
Admin
- Can: manage members and roles; create and archive workspaces; manage API keys; manage offers and rotate seller credentials; manage wallets and budgets; configure payouts; spend; and read all usage, finance, audit, and request logs (including turning request-body capture on).
- Cannot: manage billing, or withdraw payouts.
Billing admin
- Can: manage billing; manage wallets; manage budgets; configure payouts and withdraw them; and read usage, finance, audit, and payout data.
- Cannot: manage API keys, members, workspaces, or offers, and cannot spend.
Developer
- Can: spend from credit and on-chain; create and manage API keys; manage offers and rotate seller credentials; and read request logs and their own usage.
- Cannot: see the organization's bill or org-wide finance, and cannot turn on request-body capture.
Analyst
- Can: read usage, audit logs, finance, request logs, and payout position.
- Cannot: spend, move money, or change any setting. It is strictly read-only.
Member
- Can: spend from credit and view their own usage.
- Cannot: manage anything, and cannot see org-wide finance.
Viewer
- Can: view their own usage.
- Cannot: spend or change anything.
How roles are assigned
- You can only assign roles at or below your own. You cannot grant a role that carries a permission you do not hold yourself. In practice, only an owner can create another owner.
- Only an owner can change or remove another owner.
- The last owner is protected. An organization must always have at least one owner, so the last owner cannot be removed or demoted.
Change a member's role any time from Settings, then Members. See Members and invitations.