> ## Documentation Index
> Fetch the complete documentation index at: https://oximy.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> Control what each role can see and do inside Sidekick.

Sidekick has two roles: **admin** and **member**. Every person added to Sidekick holds one of these, and it determines what settings they can change and what they can see beyond their own work.

## Admin

An admin can configure Sidekick for the whole workspace, in addition to everything a member can do.

| Area                  | What an admin can do                                                                    |
| --------------------- | --------------------------------------------------------------------------------------- |
| People                | Add, enable, disable, and manage activation for anyone on Sidekick.                     |
| Access                | Configure SSO and directory sync.                                                       |
| Governance            | Approve which models, connectors, and skills are available workspace-wide.              |
| Budgets               | Set spend limits across people and projects.                                            |
| Branding and surfaces | Apply branding and connect chat surfaces.                                               |
| Approvals             | Configure which actions require approval, and grant approvals that need admin sign-off. |
| Audit                 | Review the full record of actions taken across the workspace.                           |

## Member

A member works inside Sidekick without access to workspace-wide configuration.

| Area          | What a member can do                                                                                            |
| ------------- | --------------------------------------------------------------------------------------------------------------- |
| Threads       | Start threads, use approved models, tools, connectors, and skills.                                              |
| Approvals     | Respond to consent gates on their own threads. Actions that also require admin approval still wait on an admin. |
| Sharing       | Share and collaborate on threads and projects according to the permissions granted to them.                     |
| Configuration | Cannot change workspace-wide settings such as people, access, governance, budgets, branding, or surfaces.       |

## What each role sees

An admin sees workspace-wide settings, the full people list, and the audit record for the workspace. A member sees their own threads and projects, plus anything explicitly shared with them; they don't see other people's private work or the admin configuration screens.

<Note>
  Role assignment is per person in Sidekick, not automatic from any other product. Assigning someone as admin in Sidekick doesn't change their role elsewhere in Oximy, and vice versa.
</Note>

## Broader workspace access

Sidekick's admin and member roles control Sidekick itself. Oximy's workspace-wide roles, which govern access across Visibility, Sidekick, and Relay together, are managed separately in workspace settings.

<Card title="Access and governance" icon="shield-check" href="/docs/platform/access-governance">
  How workspace membership, product entitlement, role, and resource policy combine to control access across Oximy.
</Card>
