Roles capability matrix
Ronja has four roles. Lower in this list means fewer permissions. For the concepts behind the matrix, see Roles and permissions; to assign roles, see Manage users and roles.
The four roles
Section titled “The four roles”| Role | In one line |
|---|---|
| Super Admin | The org owner. Assigned automatically to whoever creates the organization — has every permission, including promoting other members to Admin. |
| Admin | Runs the access group. Manages people, settings, and the data layer — connects sources, builds tables, and schedules jobs. |
| User | Everyday use. Explores data and asks Ronja. |
| User Read-Only | View-only access — perfect for stakeholders. |
New invitees start as User Read-Only until an admin upgrades them. A member with no role at all fails every permission check.
Capability matrix
Section titled “Capability matrix”✓ = allowed · ◐ = allowed with conditions (see footnote) · — = not allowed
| Capability | Super Admin | Admin | User | User Read-Only |
|---|---|---|---|---|
| View shared tables, data apps & knowledge | ✓ | ✓ | ✓ | ✓ |
| Run analyses & ask Ronja in explorations | ✓ | ✓ | ✓ | — |
| Create notes & knowledge (through chat) | ✓ | ✓ | ✓ | — |
| Upload files (CSV, Excel, …) | ✓ | ✓ | ✓ ¹ | — |
| Create features | ✓ | ✓ | ✓ ² | — |
| Build & edit tables | ✓ | ✓ | ◐ ³ | — |
| Connect & manage data sources | ✓ | ✓ | — | — |
| Schedule automations in shared features | ✓ | ✓ | — ⁴ | — |
| Read shared skills, secrets, workflows & data apps | ✓ | ✓ | ✓ | ✓ ⁵ |
| Create & edit shared skills, secrets, workflows & data apps | ✓ | ✓ | ◐ ⁶ | — |
| Request promotions & propose new shared resources | ✓ | ✓ | ✓ ⁷ | — |
| Connect personal MCP servers | ✓ | ✓ | ✓ | — |
| Choose the AI model & reasoning effort per chat | ◐ ⁸ | ◐ ⁸ | ◐ ⁸ | — |
| Approve promotions & note / workflow / Saved-Agent proposals; commit drafts | ✓ | ✓ ⁹ | — | — |
| Approve data app proposals | ✓ | ✓ ¹⁰ | — | — |
| View the member directory | ✓ | ✓ | ✓ | ✓ |
| Invite members & assign roles | ✓ | ✓ ¹¹ | — | — |
| Manage organization & access group settings | ✓ | ✓ | — | — |
| View every member’s explorations | ✓ | ✓ ¹² | — | — |
| Delete & restore access groups (30-day trash) | ✓ | ✓ | — | — |
| Delete & restore features (30-day trash) | ✓ | ✓ | — | — |
| Delete & restore tables (30-day trash) | ✓ | ✓ | — | — |
| Permanently purge trashed items before the 30 days | ✓ | ✓ | — | — |
| Manage access groups, features & tables through chat (admin tools) | ✓ | ✓ ¹³ | — | — |
| Promote members to Admin or Super Admin | ✓ | — | — | — |
| Buy credits | ✓ ¹⁴ | — | — | — |
| Delete the organization | ✓ ¹⁵ | — | — | — |
| Register a login domain (auto-join) | ✓ ¹⁶ | — | — | — |
Footnotes
Section titled “Footnotes”- Any member except User Read-Only can upload files in a conversation. Managing the files inside an organization-scoped feature additionally requires Admin.
- New features are private to their creator until promoted to the organization.
- Users can propose edits to shared tables as drafts; an Admin reviews and commits them. Building or editing tables directly requires Admin. This also covers writing, importing, clearing, or restoring a table’s data through chat: adding rows to, replacing, importing into, wiping, or restoring an earlier version of a table that lives in an organization-shared feature requires Admin — the same bar as creating one. A User can still freely write to their own private-feature tables and to scratch tables inside a single chat. See Versions, drafts, and approvals.
- Any member can create automations in their own private features. Automations in organization-scoped features require Admin.
- Read access to shared resources is decided by access group membership, not role — a User Read-Only member of an access group can view that access group’s shared resources. Private resources are visible only to their creator.
- Users can propose new shared resources for review (an approver decides before they go live); creating or editing shared resources directly requires Admin.
- Any member with read access to a shared feature can propose a brand-new shared note, workflow, data app, or Saved Agent there; an approver reviews it before it goes live.
- The per-chat model + effort picker is an admin-granted capability (Control Center → Models & effort). Super Admins always hold the capability (User Read-Only never does), but the picker only appears when the organization’s credit wallet has been funded and no spend downshift is active — for everyone, Super Admins included. See Govern AI spend.
- Deleting a shared MCP server requires the Admin role.
- Data app proposals and shared data-app drafts require the Admin role.
- Admins can only assign roles below their own level — an Admin cannot make someone Admin or Super Admin. You also cannot demote yourself if you are the only member at your level or higher.
- Admins can open any member’s exploration — including private ones — for support and governance. Everyone else sees only explorations shared with them.
- Each destructive admin action requested through chat still requires explicit human approval in the conversation.
- From the Billing page. Purchases are added to your next invoice — no card is charged. See Credits and AI spend.
- Only from a logged-in browser session (never via API token). The organization shuts down immediately for every member; data is permanently deleted after a 7-day cooling-off window — contact Ronja support to restore it before then.
- Only the domain of your own login email can be registered, verified via a magic link. Anyone who then logs in with a matching email joins at the chosen default role.
- Role changes can take a minute or two to apply to a member’s active session.
- Some capability differences you see in the product’s built-in Role guide have been corrected here against the actual backend behavior — where the two disagree, this page is authoritative.