Roles

Owner, admin and employee: what each role sees and can do, how roles change, and what happens when someone leaves.

Every membership carries exactly one role, and roles are scoped to your organization. A person can be an admin in one company and an employee in another; nothing crosses over.

What each role can do

CapabilityOwnerAdminEmployee
Own dashboard, scans, connected accounts
Organization overview: threats, coverage, member list
Invite and remove members; change admin ↔ employee
Domains and verification, sign-in method, SSO settings
Policies: locked packs, required clients, mailbox policy
View a member's threats (never clean mail, never content)
Audit log and CSV exports (threats, members)
Promote or demote owners
Billing, seats, plan
Off-board a member (immediate revoke + erase); delete the organization

Owner

The owner runs the company account: billing and seats, promoting or demoting other owners, deleting the organization. Owners also have every admin capability. The person who creates the organization is its first owner. At least one owner must always remain — the last owner cannot demote themselves or leave until another owner exists.

Admin

Admins run security: they see the organization overview, coverage and member list, invite and remove members, switch people between admin and employee, manage domains, the sign-in method and SSO settings, edit policies, read the audit log and export CSVs. Admins can see a member's threats — verdict, subject line or host, time — but never clean mail and never message content.

Employee

Employees are protected. They use their own dashboard, scans and connected accounts exactly like a personal user, see an organization badge, and see any locked settings as read-only (“Managed by <your organization>”). They never see another member's data.

Changing roles

  • Organization → Members → the person → Change role.
  • Admin ↔ employee: any admin or owner.
  • Promote to owner / demote an owner: owners only.
  • Roles can also come from your identity provider through a group → role map (see the SSO guides). Group-driven roles are re-applied on every login.
  • Every change is written to the audit log and takes effect within a minute — the member's existing sessions are refreshed automatically.

Removing and off-boarding

Members are either managed (the account was created through the organization: invite, SSO or auto-join) or linked (an existing personal account joined by its verified work address).

ActionManaged memberLinked member
RemoveSessions revoked, organization visibility ends, account suspended after 30 days unless the person re-homes it as personal.Membership ends; the personal account continues untouched.
Off-board (owner)Immediate revoke and erase of the account. Audited.Membership ends; personal data is not touched.

A note on “superadmin”

OKY staff operate a platform-level superadmin role for support and pilots (for example, verifying a domain by hand). Any superadmin action inside your organization is written to your audit log with the actor marked as OKY staff.