# Members and roles

> Who can see and change what in a Runbear organization.

Source: https://docs.runbear.io/administration/members-and-roles

Last updated: 2026-08-26

Everyone who uses Runbear belongs to an organization. Membership determines which
agents a person can reach, and their role determines what they can change.

## Roles

| Role       | Can do                                                   |
| ---------- | -------------------------------------------------------- |
| **Owner**  | Everything, including billing and transferring ownership |
| **Admin**  | Manage agents, integrations, and organization settings   |
| **Member** | Use agents they have access to                           |

Owners and Admins hold the organization-wide permissions to read and configure
agents. Members work with the agents they are given access to.

## Inviting and removing people

Member management runs through the hosted account pages. Open **Settings** and
select **Members**; the link opens the organization page where you invite people,
change roles, and remove access.

Removing someone from the organization revokes their access to every agent at
once, including the personal [Inbox Agent](/inbox-agent/overview.md) tied to their
account.

## Restricting a single agent

Roles govern the organization. To limit one agent to a subset of members, switch
that agent's access to restricted in its settings.

[Access control](/agents/settings.md)

## Related

- [Tool approvals](/administration/tool-approvals.md) — review which tools agents may use
- [Single sign-on](/administration/sso.md) — authenticate through your identity provider
- [Audit log](/administration/audit-log.md) — record of who changed what
