Skip to main content
Every Expanse user belongs to an organisation. Within an organisation, teams group members and control which computes each member sees. Membership and role assignment are managed from the Teams page in the Console. An organisation can define its own roles and permission sets from Security → Roles. A user has one organisation role. Team membership is a separate scope and continues to use the fixed Owner, Admin, and Member team roles.

Roles & what they unlock

Owner role

Every organisation has a protected Owner role with full authority. It cannot be edited or removed, and the organisation must retain at least one owner.

Presets and custom roles

New organisations start with editable Admin and Member presets. They can be renamed, have their permissions changed, or be removed when they are not the default and have no assigned members or pending invitations. Organisations can also create custom roles and choose which non-owner role new members receive by default. Role names are descriptive. The selected permissions determine what a member can do, including managing members, teams, security settings, billing, computes, or organisation-wide execution reads.

Assigning roles

A member who can manage organisation members may assign only roles whose permissions are a subset of their own. Only an owner or Expanse staff can grant or remove the protected Owner role. Some roles require a team placement when invited because they do not have organisation-wide execution access. The Console indicates when a team is required. If an invited email does not have an account yet, Expanse sends an invitation and adds them to the organisation with the selected role after they sign up with that email.