User Roles & Permissions
Overview
Every Tavnit user belongs to an organisation with one of four roles: Owner, Admin, Member, or Viewer. Roles control what each user can see and do across every feature in the app.
Owner
There is normally one owner — the person who created the organisation, or someone explicitly promoted to owner. The owner cannot be removed or demoted by anyone except themselves.
Owners have unrestricted access to everything:
- Create, edit, and delete flows, buckets, collections, cleaners, and matchers
- Trigger runs and view all results
- Invite and remove any team member, including other admins
- Promote or demote members to any role (including admin)
- Edit organisation name and settings
- View and manage billing and subscription
- Delete the organisation
- Set any bucket to private
- Control all bucket access — including changing admin permissions
Admin
Admins help run day-to-day operations. They can create and manage content and invite new members, but cannot touch billing, org settings, or other admins.
Admins can:
- Create, edit, and delete flows, buckets, collections, and cleaners
- Create and manage their own matchers, and edit any matcher
- Trigger runs and view all results
- Invite new members to the org (member role only)
- Remove members from the org
- Edit and delete any flow, collection, or matcher created by members
- Open the bucket access screen and change member access levels
Admins cannot:
- Edit org settings or billing
- Delete the organisation
- Set a bucket to private
- Change another admin's permissions or role
- Invite someone as admin or owner (owner only)
Member
Members are regular users. They can use flows that already exist and manage their own matchers, but cannot create flows or modify shared resources.
Members can:
- Trigger runs on existing flows and view all run results
- View flow details — including fields, webhook, email trigger, email output, data cleaning, and export to bucket settings
- Create, edit, and delete their own matchers
- Run matches on existing matchers
- View all org-visible buckets (read-only by default)
- Write data to a bucket if an admin or owner grants them editor access
Members cannot:
- Create new flows, buckets, collections, or cleaners
- Edit or delete any flow, or its fields and features
- Toggle or configure flow features (webhook, email trigger, email output, data cleaning, export to bucket)
- Edit or delete matchers created by others
- Invite or remove team members
- See private buckets unless explicitly granted access
- Access the bucket access management screen
- See the billing or org settings pages
Viewer
Viewers can see flows, runs, buckets, and cleaners but cannot create, edit, delete, or trigger any operation.
Viewers can:
- View flow configurations and run history
- View bucket data (subject to bucket visibility settings)
- View cleaner and splitter configurations
- View the Pipeline Map
Viewers cannot:
- Create, edit, or delete any resource
- Trigger runs, sweeps, or splits
- Manage team members or billing
- Change organisation settings
Permissions at a Glance
A summary of who can do what across all features.
Bucket Access System
Buckets have a two-layer access system that lets owners and admins control exactly who can see and edit each bucket independently of their org role.
Each bucket is either Org-visible (everyone in the org can see it) or Private (only the owner and users with an explicit grant can see it). Only the org owner can toggle a bucket to private.
Each user can be granted Viewer (read-only) or Editor (read + write) access to a specific bucket. These grants are stored independently of the user's org role.
To manage access, open a bucket and tap the settings icon → Manage Access. The access screen groups users by role and lets you set each person's level individually, or use the “Set all” controls to update an entire group at once.
