Roles, permissions and entity access
Access in Governax is decided by two independent things: the role you hold in the organisation, and whether you can reach a given entity. Confusing the two accounts for most access questions we get.
Two separate questions#
Holding a role does not imply reaching an entity, and reaching an entity does not imply permission to change things in it.
The five roles#
What roles actually gate today#
This is where documentation usually drifts from reality, so here is the precise position. Exactly three actions in the product check your role:
Everything else in the product, reading the ledger, listing members, running a verification, is available to any approved member who can reach the entity, regardless of role.
Which entities you can open#
Owners and admins bypass entity membership entirely and can open every entity in the organisation. Everyone else, member, billing and viewer, must be a member of the specific entity, and hitting an entity they are not a member of returns NOT_ENTITY_MEMBER.
Governax platform administrators#
Separate from organisation roles, Governax staff hold a platform administrator role used to review new workspaces and, if necessary, suspend an organisation. It is not something a customer is granted, and it is not part of your role model.
- New workspace review is described in Why a new workspace starts pending.
- Suspension and the other blocked states are described in When access is blocked.