Organization roles and permissions
What each organization role can see and change in the dashboard, the staff console and the Organization API.
Every member of an organization has one role. The roles form a ladder: each role can do everything the roles below it can, and more. The owner is the Coritan account that created the organization; Manage members and roles explains how to give a member a role.
Roles
Section titled RolesFrom the highest to the lowest:
| Role | Value | What it is for |
|---|---|---|
| Owner | owner |
Everything, including deleting the organization. There is one owner, and ownership moves only when Coritan support transfers it. |
| Admin | admin |
Everything except transferring ownership and deleting the organization. |
| Billing | billing |
Invoices, payouts, statements and customer credit, and all of Tier 3 support. |
| Tier 3 support | support_tier3 |
Every ticket, customer changes, support sessions and server work. |
| Tier 2 support | support_tier2 |
Reads any ticket, watches server consoles and logs, and works on servers customers lend from a ticket. |
| Tier 1 support | support_tier1 |
The ticket queue and their own tickets, log requests and forum report triage. |
| Read only | readonly |
Can look, cannot change. |
A member added without a role gets support_tier1. The older role name support is read as support_tier3. Billing sits above the support tiers on the ladder, but live conversations and the Discord staff links are for the owner, admins and the support tiers only.
The organization's tabs and the member API
Section titled The organization's tabs and the member APIThese are the tabs on coritan.com and the API paths behind them. "Any member" includes readonly.
| Area | Who can see it | Who can change it |
|---|---|---|
| Organization details and settings | Any member | Admin |
| Members | Any member | Admin |
| Customers and custom fields | Any member | Admin |
| Customer credit | Billing | Billing |
| Products and pricing | Any member | Admin |
| Customer services | Any member | Admin |
| Service tags | Any member | Tier 3 support |
| Invoices, statements, payouts, disputes and revenue figures | Billing | Billing |
| PayNow status, subscriptions, gift cards and affiliates | Billing | Billing; connecting the store takes an admin |
| Cloud Compute | Any member | Admin |
| DNS | Any member | Admin |
| Any member | Admin | |
| Commerce | By section, from any member to Billing | By section, from Tier 2 support to Admin |
| Apps | Any member | Admin |
| Discord and the game proxy | Admin | Admin |
| Webhooks and API keys | Admin | Admin |
| Audit log | Admin | Nobody |
| Visitor figures on the overview | Any member | Nobody |
| Deleting the organization | Owner | Owner, signed in to coritan.com |
A call below the role it needs answers 403 with Admin access required, Billing access required, Support access required or Tier 2 support access required. A Coritan account that is not a member gets 403 Not a member of this organization.
The staff console
Section titled The staff consoleThe staff console uses the same roles. The lowest role that can use each area:
| Area | Lowest role |
|---|---|
| Search, orders and the operations summary | Read only |
| The support inbox and team activity | Tier 1 support |
| Moderating the community | Tier 1 support; some tasks need Tier 3 |
| Watching server consoles and logs | Tier 2 support |
| Customers, servers, customer services and notices | Tier 3 support |
| Coupons | Tier 3 support to see them, billing to change them |
| Refund requests | Tier 3 support to see them, billing to decide them |
| Invoices, transactions, disputes, dunning and revenue insights | Billing |
| The team and the console's settings | Admin, for changes |
Within an area, some actions need a higher role than reading it does. The actions that move money, end things or open a customer's account also need a recent step-up: you confirm your password or a code from your authenticator, and the confirmation lasts 10 minutes. They include adding credit, refunding or charging an invoice, marking it paid, deciding a refund request, closing a customer's account, acting as a customer, terminating a service, restoring or deleting a backup or snapshot, and changing a teammate's role or customer account. Sign in to the staff console explains the check.
API keys
Section titled API keysAn organization API key has no role. It carries scopes instead, and it works on the Commerce API only.