Joring Docs
Admin

Teams and roles

How membership, ownership, and stackable roles decide who can do what, and how to grant them.

Joring uses an additive role model. Everyone who joins a team is a member with the same personal baseline. Everything beyond that comes from roles granted on top, and roles stack: someone can be Billing admin and Manager at once, and their access is the combination of everything they hold.

Members cannot see anyone else's data, including other members' prompts. That is a property of the privacy model rather than the role system. No role grants access to another person's conversation text. See Privacy model.

Membership

Joining a team, by invite or provisioning, confers the personal surface: coaching and trails, your own history and insights, the leaderboard, policy checks, and a read-only view of the plan and its seat counts. There is no "member role" to assign; this baseline is what membership means. Billing itself, meaning prices, the billing cycle, invoices, and the payment method, is not part of it: only the Owner, Co-owners, and Billing admins see the Billing page.

Ownership

Every team has exactly one Owner, who holds every permission including the one no role can carry: transferring ownership. Ownership moves only by transfer, from Team → People: the Owner picks a member, that person accepts or declines, and on acceptance the outgoing Owner becomes a Co-owner.

Transfer ownership before someone leaves

Ownership does not transfer automatically when an account is deprovisioned. If the Owner leaves and ownership was never moved, recovering billing control requires support. Make it part of your offboarding checklist.

The role catalog

RoleWhat it adds
AdminMembers and invites, governance, SSO and SCIM, applications, organization analytics and exports, audit log, training, trail authoring, API keys
Co-ownerEverything the Owner can do except transferring ownership. Granted and removed only by the Owner, never with an end date
Billing adminThe plan, seats, and payment details
AuditorRead-only organization insights, exports, and the audit log
IT adminMembers and invites, SSO, SCIM, API keys, and audit log reads
Security adminGovernance policies, violations, application controls, API keys, and audit reads
ManagerOrganization insights for the people in their reporting line, or for a group they manage
Trail authorWrite and publish trails for the workspace, in the console or through an AI agent

A few decisions live with the Owner and Co-owners alone and are not part of any other role: billing beyond viewing, turning data collection on or off, encryption keys, and LLM keys. These decide who can read the team's data and whose provider account processes it, so they stay with the people accountable for the team.

Granting and removing roles

Open a person from Team → People to see their roles and grant new ones. Two rules govern every grant:

  • You can only grant roles whose permissions you hold yourself. The Owner and Co-owners can grant anything; an Admin can grant every role except Billing admin and Co-owner. Nobody can grant a role to themselves.
  • Roles can carry an end date. A grant with an end date stops working the moment it passes, and expires from the list shortly after. Co-owner is the exception; it never expires.

Removing a member follows the same shape in reverse: you can remove someone only if you hold everything they hold. Co-owners are removable only by the Owner.

Roles can also come from groups: everyone in a group holds the roles assigned on it, shown as From group on their sheet. A role held through a group is not removed on the person; it ends when they leave the group or the role is unassigned from the group.

Invites can carry starting roles and groups, applied when the invite is accepted. Co-owner and Manager are never invitable; the first is Owner-assigned and the second needs a reporting line or a group that does not exist before joining. The invite dialog on the People page accepts a pasted list of up to 50 addresses, and one set of roles, groups and external settings applies to every address on it.

Managers and reporting lines

Each member can have a manager, set on their profile in Team → People. The reporting line exists for one purpose: the Manager role's visibility, which covers the holder's whole reporting line, direct reports and everyone below them.

Because the link is what the role sees, assigning a manager grants that person the Manager role automatically, and doing so requires the same authority as granting the role by hand. Clearing a link does not remove the role; remove it from the person's sheet when it is no longer wanted.

The Visibility toggle on the People page draws the reporting chart: manager nodes show how many people are in their line, and people with reports but no Manager role are flagged, with a one-click way to grant it.

Reporting lines synced from your identity provider work differently: they carry no visibility until you decide they should. See reporting lines over SCIM.

Group managers

The Manager role can also be scoped to a group. A group manager, added from the group's page, sees that group's members in organization insights; someone who also has direct reports sees their reporting line and their managed groups together. Adding a group manager needs the same authority as granting the Manager role by hand, and the scope ends when they are removed from the group page or the group is deleted.

External collaborators

Invite contractors and clients as external collaborators. Externals are badged everywhere and:

  • are never captured: data collection is disabled for them and cannot be turned on,
  • are excluded from leaderboards and analytics,
  • are not billed and do not count toward a contracted seat count (see Billing and seats),
  • can hold functional roles, but never Owner or Co-owner,
  • can carry an access end date. When it passes, access ends immediately, and the membership is cleaned up shortly after.

An external without an end date raises a review on the People page every 90 days: confirm they still need access, or remove them.

Roles and SCIM

If you provision through SCIM, the groups your identity provider pushes appear as synced groups, and the roles you assign on them follow membership from your directory. They stack with roles granted in Joring, Co-owner cannot be assigned on a group, and Owners are never changed by SCIM.

NextSingle sign-on

Connect SAML or OIDC so people sign in with your identity provider.

On this page