Roles and permissions
The four organization roles
Owner has full control of the organization, billing included, and every organization always has at least one. Admin does everything operational — members, workspaces, projects, clients, tags, reports, the audit log — but has no access to billing at all. Billing admin is the mirror image: the subscription, the payment method and the transactions, plus read-only organization details, and no time data. Member tracks their own time and reads the organization, workspaces, projects and clients they have been given.
The role shows as a chip beside each person on the Team page, and is changed from the Access tab of “Edit member details”.
Why Owner is not in the picker
The role picker offers only Member, Admin and Billing admin. Ownership is not granted like a role — it moves through Organization settings → Danger zone → Transfer ownership, which is why the owner’s own row explains “The owner’s role is changed by transferring ownership”.
A person may own at most one organization, so a transfer is refused if the recipient already owns one. You also cannot change your own role, and the owner’s row has no Archive action.
Role decides what, workspace access decides where
Owners and admins reach every workspace, so their Workspaces cell reads “All workspaces” and is not editable — the dialog says as much: the role “reaches every workspace in the organization, so there is no per-workspace access to set.”
For members and billing admins, workspace access is an explicit list. Archiving a member archives their workspace memberships too; restoring them brings back the organization membership only, so check their access afterwards. Members are archived and restored — never removed.
Three checks, not one
Every protected action passes three independent checks on the server, in order: does your role permit it, is the record inside your scope, and does the organization’s plan include the feature. A control hidden in the browser is never the enforcement — the API decides.
That is why something can be visible and still refuse. Exporting a report on the Free plan answers “This feature isn’t included in your current plan.”, and while a subscription is past due Keepr refuses new members, workspaces, projects and exports while leaving everything already tracked readable.