---
title: "Roles and permissions"
canonical: "https://support.appfire.com/space/RS/3293446483/Roles%20and%20permissions"
format: markdown
---
> Macro (aura-html)

Appfire QueueZero uses organization-level and space-level roles to control what users can access and manage.

Organization-level roles define permissions across the entire QueueZero organization. Space-level roles define permissions within an individual QueueZero space.

## Organization-level roles

| **Owner** | Owners have the highest level of access in QueueZero. They can manage organization settings, billing, spaces, connections, users, and other Owners.<br>Because Owners can manage billing and grant ownership-level access, an organization should typically have only a small number of Owners.<br>An organization must always have at least one Owner. If you try to change the role of or remove the only Owner, QueueZero requires you to promote another member to Owner first. |
| --- | --- |
| **Organization Admin** | Organization Admins can manage organization-wide settings in QueueZero.<br>Use this role for users who need to administer QueueZero across the organization but do not need Owner responsibilities such as billing access or assigning other Owners. |
| **Member** | Members are regular QueueZero users.<br>What a Member can access depends on the QueueZero spaces they are added to and their role within each space. |

## Space-level roles

Space-level roles control what a user can do within a specific QueueZero space.

| **Space Admin** | Space Admins can configure and manage their assigned QueueZero spaces.<br>They can:<br>- Manage space-level settings.
- Map Jira spaces to the QueueZero space.
- Add and manage repositories.
- Manage space knowledge and repository configuration.
- Configure space-level Code Graph and attachment settings.
- Manage access to the space.<br>Space Admins do not have permission to manage organization-wide settings unless they also have an Organization Admin or Owner role. |
| --- | --- |
| **Space Member** | Space Members can access and work within the QueueZero spaces they are assigned to.<br>They can use QueueZero to work with available Jira work items and space context, but they do not manage the space's administrative configuration. |