> ## Documentation Index
> Fetch the complete documentation index at: https://help.the-meridian.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

A role is a named set of permissions, assigned to team members to control what they can see and do. Meridian ships three default roles, and anyone with the **Roles: Edit** permission can create custom roles.

The owner sits above the role system and always passes every permission check. The owner is not a role. See [Team members](/collaborators) for how ownership works.

## Default roles

| Role | Access |
| - | - |
| **Owner** | Every permission, plus the three actions no permission grants: transferring ownership, deleting the organization, and being the one member who can't be removed or leave. Exactly one per organization; can't be restricted by anyone. |
| **Admin** | Every permission in the [catalog](/customer-permissions), across the organization and all its apps: team members, roles, billing, deleting apps and environments, restoring backups, production deploys. An admin can't remove the owner, transfer ownership or delete the organization. |
| **Member** | Every *View* permission across the organization and all apps, plus [demo mode](/demo-mode). Can't change settings, edit plans, deploy, or manage team members. |

## Custom roles

Anyone with **Roles: Edit** can create custom roles with any combination of permissions from the catalog. A non-owner can't grant a permission they don't hold themselves, which prevents privilege escalation. Ownership transfer and organization deletion are not permissions, so no role can include them. A custom role can be **scoped to specific apps**, so a member reaches only the apps that role covers. A single role can be assigned to many team members; editing a role changes access for everyone who has it.

## The permission model

Permissions come in two categories:

* **Organization permissions** apply across the whole organization regardless of app scoping: the organization itself, team members and roles, applications, billing, audit logs, [demo mode](/demo-mode) and the data export.
* **App permissions** apply within a specific app, and honour a role's app scope: integrations, credentials, App Store listing, Shopify API alerts, Plan Builder, Hosting, dev databases, database backups, Emails, Automations, CRM, Logbook and Affiliates.

The owner always retains ownership transfer and organization deletion, no matter how roles are configured, and can't be removed or locked out of anything. Everything else, billing included, is a permission that admins hold and that a custom role can be given. For the full list of permissions, see [Permissions](/customer-permissions).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.