Workspace Roles: Owner, Admin, Editor, and Viewer
The four workspace roles in AlleForge, what each one can actually do, and how permissions, audit history, and encryption work underneath them.
A workspace is the shared home for every collection, environment, and request your team owns together. Everyone in it gets one of four roles, and the role decides what they can actually do.
The four roles
| Role | What it can do |
|---|---|
| Owner | Full control over the workspace, including billing. |
| Admin | Manages requests and members — not billing. |
| Editor | Builds and edits requests day to day. |
| Viewer | Read-only access — for stakeholders who need visibility, not edit access. |
Every member is scoped to exactly the access their role grants — nothing more is implied by "being in the workspace" than what the role explicitly allows.
What's protected underneath
A few things apply regardless of role:
- Encrypted collaboration — requests and secrets are encrypted both at rest and in transit.
- Audit history — every change is attributed, timestamped, and reviewable, so "who changed this request" is always answerable.
- Activity logs — a record of who touched what, and when, across the whole workspace.
- Role management — an Owner or Admin can promote, demote, or revoke a member's access in a single click.
Changing someone's role
Promotions and revocations are immediate — there's no pending/approval step. An Admin lowering an Editor to Viewer takes effect on the next action that role would otherwise be allowed to take.
How this connects to Collections and Environments
Roles apply at the workspace level, which means they apply to everything inside it: a Viewer can open any collection or environment in the workspace, but can't edit either. An Editor can edit both. Only an Owner or Admin can manage who else is in the workspace at all.
For the real-time side of working in a shared workspace — seeing a teammate's cursor, edits, and sent requests live — see Collaboration.
See this in AlleForge
See Collaboration