Account & Security
Members and roles
The three roles in a LevelFour organization, what each one can do, and how an admin changes a role or removes someone.
Everyone in your LevelFour organization holds one of three roles. The role decides what they can change. Everyone can read everything.
Roles
| Role | What it adds |
|---|---|
| Viewer | Reads every board, cost page, saving, commitment and statement. Changes nothing. |
| Member | Everything a viewer can do, plus accepting and rejecting savings, commenting on them, requesting a rollout, and editing boards, tags and anomaly statuses. |
| Admin | Everything a member can do, plus approving a rollout someone else requested, and managing members, API keys, integrations and billing. |
A rollout that a member requests waits for an admin to approve it, so no single member can apply a change to your cloud account alone. Approvals and rollout walks through that flow.
See who has access
In the dashboard sidebar, open Settings, then Members. The Users & Access page lists everyone in the organization with their role, their last activity and the date they joined.
Search by name, or narrow the list with Filter by role.
Change a role
Open the member's row
On Settings > Members, find the person. Only an admin sees the role control and the row actions.
Pick the new role
Choose Admin, Member or Viewer from the role control on their row.
Confirm
The dialog names the old and new role. Click Change role. The new access applies right away.
Remove a member
Open the row's actions and click Remove member, then confirm. The person loses access right away.
Limits on role changes
- You cannot change your own role or remove yourself. Ask another admin.
- The last admin cannot be demoted or removed. Make someone else an admin first.
Adding people
The dashboard does not send invitations yet. To add someone to your organization, talk to your LevelFour contact. If your organization signs in through your own identity provider, Enterprise SSO covers how that works.
Next
- Enterprise SSO (SAML) signs your team in with your identity provider
- API keys are managed by admins, on the same Settings page
- Approvals and rollout is where the member and admin roles meet
Scheduled Execution
Run a LevelFour check unattended with cron or a GitHub Actions workflow, and when to take webhooks instead of a schedule.
Enterprise SSO (SAML)
Sign your team in with your own identity provider over SAML 2.0: the values you exchange with LevelFour, the attributes your IdP must send, and how to set it up in Google Workspace.