Skip to content

Roles

This page defines each access level you see in Orbit. For how a person ends up with a level — SharePoint permissions, editor seats, and admin rules — see Permissions.

Orbit shows one of three role badges for a person in a workspace:

RoleWhat it allows
ReaderOpen and read notes, follow live edits, and search the workspace. Readers never need a license.
EditorEverything a Reader can do, plus create, edit, move, share, and delete notes. Requires an editor seat.
AdminEverything an Editor can do, plus manage workspace settings and view the workspace’s member list.

Two rules decide these levels:

  • Reader vs Editor comes from your own Microsoft 365 permissions on the workspace’s OneDrive folder or SharePoint library. Write permission without an editor seat shows as Editor reach but behaves as Reader.
  • Admin is Orbit’s own rule: the workspace creator and your organization’s tenant admins are workspace admins. SharePoint permissions never grant it.

A note share carries one of two roles, chosen when the share is created:

RoleWhat it allows
Can viewRead the shared note.
Can editRead and edit the shared note. Editing through a share also requires the editor to hold a seat.

A share grants access to that one note only — never to the rest of the workspace.

Organization roles control who can use the organization tabs in settings (analytics, licenses, people, workspaces, audit):

RoleWhat it allows
MemberNormal user. No organization-wide settings access.
Tenant adminManage organization settings, licenses, and workspaces.
Tenant ownerEverything a Tenant admin can do, plus assign the Tenant owner and Tenant admin roles.

Tenant admins and owners are also workspace admins in every workspace of the organization.

See Organization admin settings for what each organization tab does.