docs/platform/access-management/rbac.md
Role Based Access Control allows a user with Administrative access to apply roles to users, granting different levels of permission within an organization or workspace.
:::info
Self-Managed Enterprise instances have an Instance Admin role in addition to the other roles outlined in this document. Airbyte assigns this role to the first user who logs on to Airbyte in a Self-Managed Enterprise instance. This user has all permissions listed below for all workspaces and all organizations associated with their Enterprise account. To update this assignment, enterprise customers should contact Airbyte support.
:::
When you assign an organization role, Airbyte scopes permissions to the entire organization, which includes all workspaces in that organization.
| Permissions | Member | Reader | Runner | Editor | Admin |
|---|---|---|---|---|---|
| Read Organization |
In a workspace role, Airbyte scopes permissions to that specific workspace. You can override an organization role by assigning someone a higher role in a workspace. However, you can't assign a role that's more restricted than the role that person holds in the organization. For example, an organization admin must also be a workspace admin. However, an organization reader can be a workspace reader, editor, or admin.
| Permissions | Reader | Runner | Editor | Admin |
|---|---|---|---|---|
| Read Workspace |
In the navigation bar, click Workspace settings or Organization settings > Members.
In the table, under Workspace role, click the current role and then select a new role.