Skip to main content
The AI Gateway implements a comprehensive role-based access control (RBAC) system that operates across two main hierarchical levels: Organisations and Workspaces. This dual-layer approach ensures precise control over who can access what resources, enhancing security while enabling effective team collaboration.

Organisation Level

Organisations represent the highest level of structure within the AI Gateway. At this level, there are three distinct roles with varying levels of administrative control:

Owner

The highest authority with complete control of the organisation

Admin

Extensive administrative privileges across the organisation

Member

Base-level organisation access, typically assigned to workspace roles

Organisation Role Permissions

Important: Organisation Owners and Admins automatically receive Admin-level access to all workspaces within the organisation. All users must first be added as Organisation Members before they can be invited to any workspace.

Workspace Level

Workspaces are sub-organisational units that enable better team and project management. Each workspace maintains its own access control structure with three distinct roles:

Admin

Complete control over workspace configuration and team management

Manager

Administrative capabilities for team and resource management

Member

Read-only access to workspace resources

Workspace Role Permissions

Member Access: Workspace Members have read-only access to workspace resources (logs, prompts, config, providers, models etc.) but cannot create, update, or delete any resources.

Access Permission Configuration

Organisation Owners and Admins can configure access permissions for various resources across workspaces. These settings determine what each role can access:
By default Workspace Admins and Managers have the same permissions unless changed by Organisation Owner or Admin.

Logs Access Permissions

Control which roles can view, filter, and export logs

Analytics Access Permissions

Control which roles can view analytics dashboards

Providers Access Permissions

Manage access to LLM providers for different roles

API Key Permissions

Configure API key creation and management rights
Key Workflow: Users must first be added as organisation members before they can be invited to any workspace. Workspace admins and managers can then invite organisation members to their workspace and assign appropriate roles.

Organisations

Workspaces

API Keys (AuthN and AuthZ)

Access Control Management

Last modified on September 15, 2026