---
title: "Manage workspaces, roles, and access"
description: "Understand organization and workspace roles and how access is scoped."
canonical: "https://memo.ly/docs/manage-workspaces-roles-and-access"
updated: "2026-07-31"
---

# Manage workspaces, roles, and access

Understand organization and workspace roles and how access is scoped.

**Who this is for:** Owners and admins managing a team.

Memo’s access model is `User → Organization → Workspace`. Organization roles are owner, admin, member, and viewer; workspace roles are workspace admin, editor, and viewer. Authorization is enforced server-side on every write.

- Invite members with single-use, expiring invitations.
- Assign roles to control who can edit, approve, export, and administer.
- Access is deny-by-default and scoped to the workspace you’re in.

> Viewers are read-only by design. If something is read-only for you, your role may be the reason.

## Expected result

You can invite people and assign the right roles.

## Common mistakes & troubleshooting

- If someone cannot access a workspace, see [I cannot access a workspace](https://memo.ly/help/i-cannot-access-a-workspace.md).

## Related
- [Create your first workspace](https://memo.ly/docs/create-your-first-workspace.md)
- [Security](https://memo.ly/security)
- [Glossary: Workspace](https://memo.ly/glossary/workspace.md)

[View HTML version](https://memo.ly/docs/manage-workspaces-roles-and-access) · [Documentation home](https://memo.ly/docs)
