Skip to content

Roles & Permissions

Wire uses role-based access control (RBAC) to manage permissions within organizations. Each member has a role that determines what actions they can perform.

RoleDescription
OwnerFull control over the organization
AdminManage members, containers, and billing
MemberCreate containers, manage the ones they created or were shared with, read-only org settings

The owner has complete control over the organization.

Permissions:

  • Create, read, update, and delete the organization
  • Manage all members (invite, remove, change roles)
  • Access billing and subscription settings
  • Full container management including admin operations
  • Container Management page: view all org containers, pause, delete, manage sharing
  • Configure organization-wide settings

Notes:

  • The user who creates an organization is automatically the owner
  • Organizations can have multiple owners
  • There must always be at least one owner

Admins can manage team members and containers but cannot modify organization-level settings.

Permissions:

  • View organization details
  • Invite new members
  • Remove members (except owners)
  • Change member roles (except to/from owner)
  • Full container management including admin operations
  • Container Management page: view all org containers, pause, delete
  • Access billing settings

Cannot:

  • Update organization name or settings
  • Delete the organization
  • Remove or demote owners
  • Manage sharing for a container they did not create and were not granted admin on

Members can create and manage their own containers and upload files. They can only access containers they created, were explicitly shared with, or that an agent created in provision mode.

Permissions:

  • View organization details and member list
  • Create containers
  • Upload and delete files in containers they have editor or admin access to
  • Update container name and description
  • Trash and restore containers
  • Invite new members
  • Use MCP tools on accessible containers
  • View any container the organization’s own agents created in provision mode

Cannot:

  • See billing balance, plan, usage, or transactions
  • See containers created by another person (unless shared)
  • Upload files to containers without an explicit editor or admin grant
  • Pause or unpause containers
  • Change container visibility
  • Change analysis cadence
  • Permanently delete containers
  • Migrate containers to another organization
  • Access the Container Management page
  • Change member roles
  • Modify organization settings
  • Purchase credits or configure billing

These permissions apply at the organization level, regardless of container grants:

ActionOwnerAdminMember
Create containers
Container Management page
Pause / unpause
Change visibility
Change analysis cadence
Permanently delete
Migrate to another org
Manage sharing for any container

Containers have two visibility settings:

  • Private - Only the creator and people with explicit grants can access
  • Public - Any signed-in Wire user who has the MCP URL gets read-only access. Their client prompts them to sign in when they connect. Write access is unaffected: it still takes a grant or being the creator. See Public Containers.

Containers use a separate permission layer from organization roles. When you share a container with someone, you assign a container-level permission:

Container PermissionAccess
ViewerView, search, explore
EditorViewer permissions, plus write, delete, and upload files
AdminFull access including settings and sharing

The container creator automatically gets admin permission. Organization owners and admins can see all containers for billing and usage purposes, but need an explicit grant to edit containers they didn’t create. Managing a container’s grants is narrower still: it takes an admin grant on that container, or being its creator, or being an organization owner.

A container that one of your organization’s own agents created with an organization API key (provision mode) belongs to the organization instead of to a person. Because there is no creator to be private to, access is decided by organization role alone:

RoleAccess to a provision-mode container
OwnerAdmin: read, write, and manage settings, sharing, and deletion
AdminAdmin: read, write, and manage settings, sharing, and deletion
MemberViewer: read its contents, no changes

No grant is involved, and nobody has to share the container for a member to see it. Every member of the organization gets read access from the moment the container is created. These containers are listed under a Provisioned tab on the Containers page, attributed to the agent that created them.

This is the one case where a container is readable across the whole organization without being explicitly shared. Containers a person creates stay private to that person until they share them.

See Sharing Containers for a step-by-step guide.

  1. Go to Organization Settings
  2. Click Members
  3. Click Invite Member
  4. Enter email and select role
  5. Click Send Invitation

The invited user will receive an email with a link to join your organization.

  1. Go to Organization SettingsMembers
  2. Find the member
  3. Click on their current role
  4. Select the new role
  1. Go to Organization SettingsMembers
  2. Find the member
  3. Click Remove
  4. Confirm removal

Removing a member immediately revokes their access to all containers in the organization.