New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Roles and permissions in the Ory Console

The Ory Console uses role-based access control enforced through Ory Keto. Roles are assigned at two levels: workspace and project.

Workspace roles​

A workspace has three roles: Owner, Developer, and Viewer.

Owner​

The Owner role has full administrative control over the workspace.

  • View and edit workspace metadata
  • Upgrade the workspace plan
  • View and manage billing
  • View and manage members
  • Create and delete workspace API keys
  • Create projects and view the projects list

Developer​

The Developer role provides day-to-day access without administrative capabilities.

  • View workspace metadata
  • Create projects and view the projects list
  • View members
  • View workspace API keys

Developers cannot:

  • Edit workspace metadata
  • Manage billing
  • Manage workspace members
  • Create or delete workspace API keys

Viewer​

The Viewer role is read-only. Viewers can see how the workspace is set up, but cannot change anything or create projects.

  • View workspace metadata
  • View the projects list
  • View members
  • View workspace API keys

Viewers cannot:

  • Create projects
  • Edit workspace metadata
  • View or manage billing
  • Manage workspace members
  • Create or delete workspace API keys

Workspace permission matrix​

PermissionOwnerDeveloperViewer
View workspace metadataYesYesYes
Edit workspace metadataYesNoNo
Upgrade workspace planYesNoNo
View billingYesNoNo
Manage billingYesNoNo
View membersYesYesYes
Manage membersYesNoNo
View workspace API keysYesYesYes
Create/delete workspace API keysYesNoNo
Create projectsYesYesNo
View projects listYesYesYes

Project roles​

A project has three roles: Owner, Developer, and Viewer.

Owner​

The Owner role has full control over the project, including destructive and administrative actions. Owners inherit all Developer permissions.

In addition to Developer permissions, Owners can:

  • Delete the project
  • Move the project between workspaces
  • Upgrade the project plan
  • Add and remove collaborators
  • Modify project workspace settings

Developer​

The Developer role provides full access to project configuration and all Ory services.

  • Read and write project configuration
  • View collaborators
  • Manage project API keys
  • Manage custom domains (CNAMEs)
  • Manage event streams
  • Full access to Ory Identities (read/write identities, credentials, sessions, and messages)
  • Full access to Ory Permissions (read/write relationships, read permissions)
  • Full access to Ory OAuth2 (read/write clients)

Developers cannot:

  • Delete or move the project
  • Add or remove collaborators
  • Modify project workspace settings

Viewer​

The Viewer role is read-only. Viewers can inspect how a project is configured, but cannot change it and cannot reach the data the project stores.

  • Read the project configuration
  • View collaborators
  • View project API keys
  • View custom domains (CNAMEs)
  • View event streams

Viewers cannot:

  • Change any project configuration
  • Read or write identities, credentials, sessions, or messages
  • Read or write relationships, or check permissions
  • Read or write OAuth2 clients

Project permission matrix​

PermissionOwnerDeveloperViewer
Read project configurationYesYesYes
Export configuration (CLI, API)YesYesNo
Write project configurationYesYesNo
View collaboratorsYesYesYes
Add/remove collaboratorsYesNoNo
View project API keysYesYesYes
Create/delete project API keysYesYesNo
View custom domains (CNAMEs)YesYesYes
Manage custom domains (CNAMEs)YesYesNo
View event streamsYesYesYes
Manage event streamsYesYesNo
Ory Identities (full read/write)YesYesNo
Ory Permissions (full read/write)YesYesNo
Ory OAuth2 (full read/write)YesYesNo
Delete projectYesNoNo
Move projectYesNoNo
Upgrade project planYesNoNo
Modify workspace settingsYesNoNo

Managing roles​

To change a member's role, a workspace Owner can go to Workspace settings → Members in the Ory Console.

Workspace members

For more information on workspaces and member management, see Workspaces & Environments.