Roles & Permissions

Wytness uses a four-tier role model to control access within each organisation. Roles are hierarchical — each higher role inherits everything from the ones below it.

Role Overview

RoleLevelDescription
OwnerHighestFull control over the organisation including billing, plan changes, and all team management. Every org must have at least one Owner.
AdminHighManage team members, API keys, and SIEM webhooks. Can invite and manage Members and Viewers, but cannot manage other Admins or Owners.
MemberStandardDay-to-day access to the audit trail with the ability to export data (CSV, JSONL).
ViewerRead-onlyView-only access to events, sessions, agents, and the team list. Cannot modify or export anything.

Permission Matrix

The table below shows exactly what each role can do. Permissions are cumulative — each role includes everything from the roles below it, plus additional capabilities.

CapabilityViewerMemberAdminOwner
View events & sessionsYesYesYesYes
View agents & registryYesYesYesYes
View team membersYesYesYesYes
Export data (CSV/JSONL)YesYesYes
Manage API keysYesYes
Manage SIEM webhooksYesYes
Invite & manage teamYesYes
Manage billing & planYes
Transfer ownershipYes

Role Details

Owner

Owners have unrestricted access to every feature in the organisation. They are the only role that can manage billing, change the subscription plan, and promote or demote Admins. Every organisation must retain at least one active Owner — the platform prevents demoting or disabling the last Owner.

Admin

Admins handle day-to-day operational management. They can invite new team members (as Member or Viewer), disable accounts, rotate API keys, and configure SIEM webhook endpoints. Admins cannot invite other Admins, change an Admin's role, or access billing settings.

Member

Members are the standard working role. They have full read access to the audit trail and can export data for analysis. They cannot make any configuration changes to the organisation.

Viewer

Viewers have read-only access. They can browse the event stream, view agent profiles, and see the team list, but cannot export data or make any changes. This role is ideal for stakeholders who need visibility without operational access.

Key Behaviours

Note
Roles are assigned at the organisation level. A user has exactly one role per organisation.
BehaviourDetail
Last Owner protectionThe platform prevents demoting or disabling the only remaining Owner in an organisation.
Admin scope limitsAdmins can only manage users at a lower level (Members and Viewers). They cannot modify peers or superiors.
Role assignment on inviteWhen inviting a new team member, the inviter selects the role. Admins can invite Members and Viewers. Owners can invite any role.
Invitation expiryInvitations expire after 7 days. They can be resent (generating a new token) or cancelled by any Admin or Owner.
Account disablingDisabled accounts cannot log in. All active sessions and refresh tokens are revoked immediately. The account can be re-enabled at any time.
Self-modificationUsers cannot change their own role or disable their own account. These actions must be performed by another Admin or Owner.

Ready to audit your AI agents?

Start recording

We set no cookies. Sign-in and preferences use essential first-party browser storage only — no tracking, advertising, or third-party analytics. Privacy Policy

Roles & Permissions
TABLE OF CONTENTS