Skip to Content
ReferenceRoles and Permissions

Roles and Permissions

Lunaris uses workspace roles for shared content and administration. Private projects give selected workspace members a separate project role.

Workspace roles

CapabilityOwnerEditorViewer
Open workspace projects and contentYesYesYes
Create and edit Shared-project contentYesYesNo
Create and manage projectsYesYesNo
View workspace membersYesYesYes
Invite, remove, or change membersYesNoNo
Manage workspace detailsYesNoNo
Manage extensionsYesNoNo
Create and view backupsYesNoNo
View Audit logYesNoNo
Manage billingYesNoNo
Delete workspaceYesNoNo

Owner

Owner is the administrative role. Owners control workspace access, extensions, backups, billing, and the Audit log in addition to normal project work. The workspace owner cannot be removed or changed to another role.

Editor

Editors can create, rename, update, and delete projects and content. They can see the member list but cannot invite people or manage workspace administration.

Viewer

Viewers can open Shared projects and content without changing them. A Private project can separately grant that member Editor or Viewer access.

Personal workspaces do not support additional members. In a shared workspace, an owner can invite new members as Editor or Viewer from Workspace Settings → Members.

Private-project roles

Private projects add a second access decision:

Project accessWhat it allows
Project ownerControls private access, can change visibility, and can transfer project ownership.
EditorCan open and change that project’s content.
ViewerCan open the project without changing it.
No project accessCannot find or open the Private project.

Private-project access can only be granted to existing workspace members. The project owner can change a member between Editor and Viewer, remove their access, or transfer project ownership to an eligible workspace member.

Shared projects do not use individual project roles. Every workspace member can open them, and their workspace role determines what they can do. Local projects have no roles because they never leave their browser profile.

See Invite People and Share Projects for the sharing workflow.