AnyInt Docs
Enterprise

Roles and Permissions

Roles define who can manage organizations, projects, keys, usage visibility, billing, and security settings.

Roles define who can manage organizations, projects, keys, usage visibility, billing, and security settings.

Current role model

RoleTypical ownerMain responsibility
AdminPlatform or IT leadOrganization-wide control
Project OwnerTeam or product leadProject-level operations
MemberDeveloper or builderDay-to-day API usage
FinanceBilling ownerBilling and invoices

Practical access split

AreaAdminProject OwnerMemberFinance
organization settingsfullnonenonenone
member managementfullproject-scopednonenone
key managementfullproject-scopedown resources onlynone
usage visibilityfullproject-scopedown or assigned contextnone
billing and invoicesfullnonenonefinance workflows

Project scoping matters

Project Owner and Member permissions are limited by project context:

  • Project Owner manages people, keys, and usage inside the current project
  • Member works only with their own or assigned project resources

Assignment guidance

SituationRecommended role
User must manage organization settings, SSO, members, and billing ownershipAdmin
User owns one product team or environmentProject Owner for that project
User only needs to call APIs or view assigned resourcesMember
User handles invoices, renewals, or finance reviewFinance

Separation of duties

For production organizations, avoid putting every responsibility on one shared admin account.

DutyRecommended owner
Key creation and rotationAdmin or Project Owner
Day-to-day API usageMember or service account key owned by a project
Billing reviewFinance owner, with Admin visibility if needed
SSO and security policyAdmin plus security owner
Usage investigationAdmin for organization-wide view, Project Owner for project scope

Access review checklist

Review role assignments regularly and after team changes:

  1. Remove users who no longer need access.
  2. Downgrade Admins who only need project-level control.
  3. Confirm production API keys still have a named owner.
  4. Confirm finance users can reach invoice and renewal workflows.
  5. Check that each project has at least one accountable owner.

Fine-grained permissions

The table above is an outcome-level map. Enterprise accounts may use additional fine-grained controls depending on rollout stage and account configuration.

On this page