Skip to main content
Access in Keydris is governed by per-organization roles. Each member holds a role, and that role determines which surfaces they see and which actions they can take. The navigation only shows what a role can access, and the API enforces every action regardless of the UI, so hiding a screen is never the only safeguard.

System roles

RoleAccess
AdminFull access to every resource and setting.
UserDay-to-day operator access, minus organization and member administration.
ManagementReserved role. No permissions granted yet.
AccountingReserved role. No permissions granted yet.
System roles are protected from edits. You can review exactly what each role grants under Settings then Roles.

Permissions

Permissions are grouped by area:
GroupPermissionWhat it grants
OrganizationManage organizationCreate, rename, and archive organizations.
OrganizationManage membersInvite members and change their roles.
AgentsManage agentsCreate, edit, and revoke autonomous agents.
AgentsView agentsBrowse the agent directory and details.
PoliciesManage policiesAuthor and version policies.
PoliciesView policiesRead policy definitions and version history.
PaymentsManage payment instrumentsAdd or remove stored payment instruments.
PaymentsView payment instrumentsView stored payment instruments.
AuditView decisionsInspect authorization allow and reject decisions.
AuditView audit logRead the tamper-evident audit trail.
If you cannot see a page or setting, your role likely does not include the matching permission. Ask an organization Admin to update your role.