Skip to main content
Use roles and access levels together when you need to decide what someone can do in a workspace and on a specific shared resource.

Organization roles

Runway roles are strictly hierarchical: Owner > Admin > Manager > Member > Guest > Anonymous user. A user’s role caps what per-resource access can grant.

Default capability matrix

This matrix shows the default system ACLs seeded for each role. A check means the default ACL grants that capability; a dash means it is not granted by the default ACL or is explicitly denied. Guest and Anonymous user have no default ACLs; they only receive access that is explicitly shared.

Resource access levels

Role and resource access combine by taking the narrower result: the role sets the user’s maximum workspace capability, and the resource access level controls what they can do on a specific page, section, block, scenario, or database column.

What’s next