Every membership carries exactly one role, and roles are scoped to your organization. A person can be an admin in one company and an employee in another; nothing crosses over.
What each role can do
| Capability | Owner | Admin | Employee |
|---|---|---|---|
| Own dashboard, scans, connected accounts | ✓ | ✓ | ✓ |
| Organization overview: threats, coverage, member list | ✓ | ✓ | — |
| Invite and remove members; change admin ↔ employee | ✓ | ✓ | — |
| Domains and verification, sign-in method, SSO settings | ✓ | ✓ | — |
| Policies: locked packs, required clients, mailbox policy | ✓ | ✓ | — |
| View a member's threats (never clean mail, never content) | ✓ | ✓ | — |
| Audit log and CSV exports (threats, members) | ✓ | ✓ | — |
| Promote or demote owners | ✓ | — | — |
| Billing, seats, plan | ✓ | — | — |
| Off-board a member (immediate revoke + erase); delete the organization | ✓ | — | — |
Owner
The owner runs the company account: billing and seats, promoting or demoting other owners, deleting the organization. Owners also have every admin capability. The person who creates the organization is its first owner. At least one owner must always remain — the last owner cannot demote themselves or leave until another owner exists.
Admin
Admins run security: they see the organization overview, coverage and member list, invite and remove members, switch people between admin and employee, manage domains, the sign-in method and SSO settings, edit policies, read the audit log and export CSVs. Admins can see a member's threats — verdict, subject line or host, time — but never clean mail and never message content.
Employee
Employees are protected. They use their own dashboard, scans and connected accounts exactly like a personal user, see an organization badge, and see any locked settings as read-only (“Managed by <your organization>”). They never see another member's data.
Changing roles
- Organization → Members → the person → Change role.
- Admin ↔ employee: any admin or owner.
- Promote to owner / demote an owner: owners only.
- Roles can also come from your identity provider through a group → role map (see the SSO guides). Group-driven roles are re-applied on every login.
- Every change is written to the audit log and takes effect within a minute — the member's existing sessions are refreshed automatically.
Removing and off-boarding
Members are either managed (the account was created through the organization: invite, SSO or auto-join) or linked (an existing personal account joined by its verified work address).
| Action | Managed member | Linked member |
|---|---|---|
| Remove | Sessions revoked, organization visibility ends, account suspended after 30 days unless the person re-homes it as personal. | Membership ends; the personal account continues untouched. |
| Off-board (owner) | Immediate revoke and erase of the account. Audited. | Membership ends; personal data is not touched. |
A note on “superadmin”
OKY staff operate a platform-level superadmin role for support and pilots (for example, verifying a domain by hand). Any superadmin action inside your organization is written to your audit log with the actor marked as OKY staff.