Two independent role systems
Ragen AI has two role systems that operate completely independently. Confusing them is the most common way to misread what someone can or cannot do.Organization Role
Controls what you can do inside one organization. Stored as one row per person per organization. Granted by that organization’s owner or admin.
Platform Role
Controls access to the admin panel — a separate application. Applies across the entire installation. Granted by another platform administrator.
Organization roles
Your organization role determines what you can see and manage within a single organization.admin and owner have identical day-to-day permissions. The only difference is that only the owner can dispose of the organization itself — transfer it to another owner or delete it entirely.
Platform role
The platform role (admin or user) controls access to the admin panel — a separate application used for cross-organization management. Platform admins can view usage across every organization, manage disk ceilings, revoke API keys, and access the activity log. Having a platform role does not grant membership in any organization and does not allow reading another organization’s documents through the main application.
Document permissions
Within an organization, individual files and folders carry their own visibility rules. Permissions are set at creation time based on ownership, and can be extended through explicit sharing.
You can grant access at two levels:
- View — the document is included in retrieval results and the user can read its content
- Full access — the user can also edit, move, and delete the document