> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stoutdata.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles and permissions

> What owners, admins, and members can do in a Stout organization.

Each person in an organization has one role: **Owner**, **Admin**, or **Member**. The role decides what the person can do. Stout checks the role on the server for each action.

Owners and admins have the same permissions, except for some organization settings that only an owner can change. The tables on this page show owners and admins in one column, and they mark each action that only owners can do. Members can use only the boxes that an owner or admin assigns to them.

The dashboard sometimes shows a control that a member cannot use. If a member selects that control, Stout refuses the action.

Stout does not let anyone remove or demote the last owner of an organization.

## Boxes

| Action                                                 | Owners and admins | Members             |
| ------------------------------------------------------ | ----------------- | ------------------- |
| See boxes and open box pages                           | All boxes         | Assigned boxes only |
| Add, edit, import, or delete boxes                     | Yes               | No                  |
| Install or uninstall Stout, and update Stout or Lager  | Yes               | No                  |
| Add, edit, or delete nets, and save or apply templates | Yes               | No                  |
| Create and manage box groups                           | Yes               | No                  |
| Upload box photos                                      | Yes               | No                  |
| Start, stop, and adjust webcam streams                 | Yes               | No                  |
| Assign boxes to members                                | Yes               | No                  |
| Set variables for one box                              | Yes               | No                  |

## Locks

| Action                                                                              | Owners and admins | Members |
| ----------------------------------------------------------------------------------- | ----------------- | ------- |
| Lock and unlock a box for yourself                                                  | Yes               | Yes     |
| Force unlock a box that another person holds                                        | Yes               | No      |
| Send a command from a Workbench instrument panel to a box that another person holds | No                | No      |

You must have a display name before you can lock a box. A lock does not stop an owner or admin from editing, updating, or deleting a box. See [Locks](/source/boxes/locks).

<Warning>
  Do not depend on a lock alone to keep other people off a box. A lock does not stop a UART console, a firmware flash, a script from **Import Test**, or a Factory run. Tell the people who share the box before you start work that must not be interrupted.
</Warning>

## Workbench and tests

| Action                                                       | Owners and admins | Members             |
| ------------------------------------------------------------ | ----------------- | ------------------- |
| Open Workbench and see nets                                  | Yes               | Yes                 |
| Control instruments, flash firmware, and open a UART console | Yes               | No                  |
| Run a repository test from **Select Test**                   | Yes               | Assigned boxes only |
| Run a script with **Import Test**                            | Yes               | Assigned boxes only |
| Choose the repository and tests path for **Select Test**     | Yes               | No                  |

## Factory

| Action                                    | Owners and admins | Members |
| ----------------------------------------- | ----------------- | ------- |
| See suites, runs, and run results         | Yes               | Yes     |
| Import, edit, and delete suites           | Yes               | No      |
| Start and cancel runs                     | Yes               | No      |
| Answer operator prompts during a live run | Yes               | Yes     |

## Organization and settings

| Action                                                               | Owners and admins | Members |
| -------------------------------------------------------------------- | ----------------- | ------- |
| Change the organization name, slug, and default box username         | Owners only       | No      |
| Delete the organization                                              | Owners only       | No      |
| Configure SSO                                                        | Owners only       | No      |
| Invite members and admins                                            | Yes               | No      |
| Invite owners                                                        | Owners only       | No      |
| Give the **Owner** role, or change the role of an owner              | Owners only       | No      |
| Change the role of an admin or a member                              | Yes               | No      |
| Remove people from the organization                                  | Yes               | No      |
| Unlock accounts and make password reset links                        | Yes               | No      |
| Set feature access for members                                       | Yes               | No      |
| Manage integrations, organization variables, and CI keys             | Yes               | No      |
| Read the audit log                                                   | Yes               | No      |
| Edit your own account, password, SSH keys, and notification settings | Yes               | Yes     |

To save an SSO configuration, an owner must also have a verified email address. See [Single sign-on](/source/integrations/sso).

## Features that your organization controls

A member sees a feature such as Workbench or Factory only when two things are true. Your organization must have the feature, and the member's feature access must allow it. Feature access controls what a member sees in the dashboard. It does not change the permissions on this page. See [Members and invitations](/source/organizations/members-and-invitations).

## The Developer role

Stout staff who help your organization show the role **Developer** on the **Team Permissions** page. They do not have an owner, admin, or member role in that list.
