Skip to content

Roles & permissions

Every member of an ALIGN organization has one of four roles. Roles are fixed — you choose the right one when you invite someone, and an Admin can change it at any time. This page is the reference for what each role allows; inside ALIGN, the same matrix is one click away behind the Roles button on the Members & Teams page.

Role In short
Owner Everything an Admin can, plus billing and the life of the organization. Exactly one per organization — the role only moves through an ownership transfer.
Admin Manages members and settings, edits all organization content.
Editor Creates, imports and publishes; edits their own content.
Viewer Reads shared content in the Map Viewer profile. Free on per-seat plans — viewers never consume a seat.
Capability Viewer Editor Admin Owner
Viewing — View shared content (Datastore, shared and published maps, personal OGC keys)
Building — Access the Map Builder and App Builder —¹
Building — Use the AI assistants (AI Assistant, AI Builder, including Ask) —²
Content — Create, import and publish; edit own content
Content — Edit others’ content
Content — Export and download Datastore content
Members & Teams — Manage members, invitations and teams
Organization — Organization settings (AI indexing, integrations exposure)
Organization — Connect personal integrations (GitHub, Supabase) ✓³
Billing — View billing (plan, invoices, capacity)
Billing — Purchase and change plans, seats, add-ons and credits
Organization — Rename or delete the organization, transfer ownership

¹ A viewer’s surface is the read-only Map Viewer profile of the Map Builder: navigation, identify, layers and the attribute table — no editing, no saves.

² An admin can grant the AI Assistant to an individual viewer (off by default, reset when the role changes). The viewer’s AI usage is billed to the organization’s credits.

³ Limited to the providers the organization chooses to expose.

Every rule in this matrix is enforced by the ALIGN servers — hiding a button is a courtesy, the permission check is the guarantee.

On per-seat plans (Team and Enterprise), only roles that write consume a seat: Owner, Admin and Editor each hold one, Viewers are free and unlimited up to a fair-use cap. This is why the role you pick at invitation time is also a billing decision.

There is exactly one Owner per organization. The role is not assigned through invitations or role changes: it only moves through an ownership transfer, initiated by the current Owner from the organization settings. The recipient must accept — and on a subscribed organization, take over the payment method — before anything changes. The former Owner keeps working with the exit role they chose.

  • See the matrix: the Roles button, on the Members & Teams page (every member) and in Settings → Organization → Members & Teams (admins).
  • Change a member’s role: the role select in the members table, Admin and Owner only. The member is notified of the change.
  • Invite with a role: the role is chosen in the invite dialog and can be changed later.