Skip to content

Roles Reference

This page summarizes the roles you may see in Orbit.

Workspace roles come from Microsoft 365-backed access.

RoleMeaning
readCan view accessible workspace content.
writeCan create and edit workspace content where Microsoft 365 allows it.
managerCan manage workspace-level settings when that role is shown for the workspace.
ownerOwns or administers the connected Microsoft 365 location when Microsoft 365 grants that authority.

Note-specific shares use simpler roles.

RoleMeaning
readCan view the shared note.
writeCan edit the shared note.

Tenant roles control organization admin access.

RoleMeaning
memberNormal user.
tenant adminCan access admin views where allowed.
tenant ownerCan manage tenant roles and high-risk tenant actions.

If someone has access through more than one route, the effective result depends on Microsoft 365 permissions and any note-specific share. When in doubt, review the Microsoft 365 location and Orbit’s manage access view.