Auron
Configure AuronGetting Started

Roles & Permissions

The roles available in an organization and what each one can do.

Every user has exactly one role per organization, and that role is what every permission check in Auron is ultimately evaluated against. The same role governs what's reachable from the console, the mobile app, and any MCP or API connection made as that user.

The roles

An owner has full control, including things admins can't touch, such as changing who owns the organization. An admin configures agents, knowledge, entities, automations and most organization settings, and manages users and teams. A user gets the working role: starting and joining conversations, creating and updating entity records, running meetings, using knowledge stores, the day-to-day surface, without configuration access. A guest gets the narrowest role: listing the organization and reading conversations and signals, with no ability to create or configure anything.

How it's enforced

Every action, not just every screen, is checked against the calling user's role and resource. Creating a conversation, updating a record, viewing analytics are each their own permission rather than one blanket "can use the app" flag. This is the same check whether the request comes from the web console, the mobile app, or Auron in Claude acting on someone's behalf.

Where this is managed

Assigning roles happens in the console under Access. This page covers what each role means; that one covers changing it.

On this page