---
title: Users and roles
description: The four roles, what each can do, and how to change someone's role.
---

_[console.superalign.ai/users](https://console.superalign.ai/users)_

The Users page shows a count per role and a table of everyone with **User**, **Email**, **Role**, and **Last Active**.

| Role | Can |
| --- | --- |
| **Owner** | Everything. The person who created the organization |
| **Admin** | Everything: see all data, make decisions, change extensions, create tokens, change roles |
| **Viewer** | See every page, including sessions and the audit log. Change nothing |
| **Member** | See only their own laptop and the Downloads page |

Laptops enrolled through MDM get the role of the person they are assigned to, or Member if no person is set. That decides what the laptop's own desktop app can show.

## Before you begin

- You have the **Owner** or **Admin** role. Other roles see the list but cannot change it.

## Change a role

1. **Find the person**

    On the Users page, find their row.

2. **Click the role badge**

    Choose **Admin**, **Member**, or **Viewer**.

The change is immediate and written to the [audit log](/surface/admin/audit-log). You cannot change your own role. The Owner role cannot be given from the console.

## Keeping the list in sync

Connect [Google Workspace](/surface/extensions/integrations/google-workspace) or [Entra ID or Okta](/surface/extensions/integrations/entra-okta) and the Users page follows your directory.

## Next steps

- [Connect Google Workspace](/surface/extensions/integrations/google-workspace) or [Entra ID or Okta](/surface/extensions/integrations/entra-okta) to sync users automatically
- [Audit log](/surface/admin/audit-log) to see every role change
