> ## Documentation Index
> Fetch the complete documentation index at: https://help.casaconect.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> What organization admins and members can do, how projects narrow access further, and where Shared Spaces and the agent fit in.

Access in Casa Conect is decided at three levels: your **role in the organization**, your **membership of a project**, and, inside a Shared Space, your **permissions on each kind of document**. The agent sits on top of all three with no access of its own.

## Organization roles

There are two roles: **Admin** and **Member**.

| Capability                                                                         |           Member          |      Admin      |
| :--------------------------------------------------------------------------------- | :-----------------------: | :-------------: |
| Use the agent, matters, the editor, the inbox and the vaults                       |            Yes            |       Yes       |
| See the organization vault and organization-wide projects                          |            Yes            |       Yes       |
| See **private** projects                                                           | Only those they belong to |     **All**     |
| Create projects and matters                                                        |            Yes            |       Yes       |
| Manage a project: settings and members                                             |         Its owner         | **Any project** |
| Move a matter between projects                                                     |  Its creator or assignee  |       Yes       |
| Connect their own Drive, OneDrive or SharePoint account                            |            Yes            |       Yes       |
| See and unlink **every** synced folder in the organization                         |             No            |       Yes       |
| Write personal skills and personal guidance                                        |            Yes            |       Yes       |
| Write **organization** skills and **organization** guidance                        |             No            |       Yes       |
| Share a matter template with the organization                                      |             No            |       Yes       |
| Approve a held email, or deny it                                                   |            Yes            |       Yes       |
| **Always allow** or **block** a sender                                             |             No            |       Yes       |
| Configure the agent inbox: reply policy, sender mode, domains, suppressions        |             No            |       Yes       |
| Delete an inbox conversation                                                       |             No            |       Yes       |
| Set the [permission level](/agent/permission-levels) for the inbox and for matters |             No            |       Yes       |
| Set [model policies](/models/model-policies)                                       |             No            |       Yes       |
| View plan, credits and usage                                                       |            Yes            |       Yes       |
| Change plan, payment details, budgets and member limits                            |             No            |       Yes       |
| Invite, remove and change the role of members                                      |             No            |       Yes       |
| Rename or delete the organization                                                  |             No            |       Yes       |

<Note>
  Admins can see every project so that work is never stranded when someone is away. Admins **cannot** see a member's **personal vault** or **private conversations** with the agent.
</Note>

## Projects

A **project** groups the vault, matters and conversations for one piece of business: a transaction, a client, a development.

| Project access   | Who can see it                       |
| :--------------- | :----------------------------------- |
| **Organization** | Every member of the organization     |
| **Private**      | Its members, and organization admins |

Within a project, the **owner** manages its settings and members, and **members** work in it.

Everything in a project inherits its access: its vault, its matters, and the conversations shared in it. A conversation from a private project that is linked to a matter stays hidden from anyone who cannot see that project. They are told only how many linked conversations they cannot see.

## Shared Spaces

Shared Spaces have their own, finer-grained model, because they include people **outside** your organization: buyers, sellers, the other side's lawyer, the notary, the bank.

* People are invited to a space individually, and can be grouped into **teams**.
* Access is granted **per document type** and **per summary category**, as *viewer* or *editor*. A person sees only the document types and summary categories they have been given.
* Document types can have **owners**, responsible for providing them, and **reviewers**, responsible for approving them.

See [Members and teams](/shared-spaces/members-and-teams).

## The agent

The agent has **no role of its own**. In any conversation it acts as the person who started it, with that person's organization role, project memberships and Shared Space permissions. Asking the agent cannot get around a restriction that applies to you. See [Access control](/security/access-control#the-agents-access).

## Good practice

* **Keep at least two admins**, and no more than you need.
* **Use private projects** for matters that should be seen by a small team.
* **Review members each quarter.** Remove people who have left, and check pending invitations.
* **Ask everyone to enable [two-factor authentication](/admin/account-and-sign-in#two-factor-authentication).**
