Roles & Permissions
Wire uses role-based access control (RBAC) to manage permissions within organizations. Each member has a role that determines what actions they can perform.
Roles Overview
Section titled “Roles Overview”| Role | Description |
|---|---|
| Owner | Full control over the organization |
| Admin | Manage members, containers, and billing |
| Member | Create containers, manage the ones they created or were shared with, read-only org settings |
The owner has complete control over the organization.
Permissions:
- Create, read, update, and delete the organization
- Manage all members (invite, remove, change roles)
- Access billing and subscription settings
- Full container management including admin operations
- Container Management page: view all org containers, pause, delete, manage sharing
- Configure organization-wide settings
Notes:
- The user who creates an organization is automatically the owner
- Organizations can have multiple owners
- There must always be at least one owner
Admins can manage team members and containers but cannot modify organization-level settings.
Permissions:
- View organization details
- Invite new members
- Remove members (except owners)
- Change member roles (except to/from owner)
- Full container management including admin operations
- Container Management page: view all org containers, pause, delete
- Access billing settings
Cannot:
- Update organization name or settings
- Delete the organization
- Remove or demote owners
- Manage sharing for a container they did not create and were not granted admin on
Member
Section titled “Member”Members can create and manage their own containers and upload files. They can only access containers they created, were explicitly shared with, or that an agent created in provision mode.
Permissions:
- View organization details and member list
- Create containers
- Upload and delete files in containers they have editor or admin access to
- Update container name and description
- Trash and restore containers
- Invite new members
- Use MCP tools on accessible containers
- View any container the organization’s own agents created in provision mode
Cannot:
- See billing balance, plan, usage, or transactions
- See containers created by another person (unless shared)
- Upload files to containers without an explicit editor or admin grant
- Pause or unpause containers
- Change container visibility
- Change analysis cadence
- Permanently delete containers
- Migrate containers to another organization
- Access the Container Management page
- Change member roles
- Modify organization settings
- Purchase credits or configure billing
Organization-Level Container Permissions
Section titled “Organization-Level Container Permissions”These permissions apply at the organization level, regardless of container grants:
| Action | Owner | Admin | Member |
|---|---|---|---|
| Create containers | ✓ | ✓ | ✓ |
| Container Management page | ✓ | ✓ | ✗ |
| Pause / unpause | ✓ | ✓ | ✗ |
| Change visibility | ✓ | ✓ | ✗ |
| Change analysis cadence | ✓ | ✓ | ✗ |
| Permanently delete | ✓ | ✓ | ✗ |
| Migrate to another org | ✓ | ✓ | ✗ |
| Manage sharing for any container | ✓ | ✗ | ✗ |
Container-Level Access
Section titled “Container-Level Access”Visibility
Section titled “Visibility”Containers have two visibility settings:
- Private - Only the creator and people with explicit grants can access
- Public - Any signed-in Wire user who has the MCP URL gets read-only access. Their client prompts them to sign in when they connect. Write access is unaffected: it still takes a grant or being the creator. See Public Containers.
Container Grants
Section titled “Container Grants”Containers use a separate permission layer from organization roles. When you share a container with someone, you assign a container-level permission:
| Container Permission | Access |
|---|---|
| Viewer | View, search, explore |
| Editor | Viewer permissions, plus write, delete, and upload files |
| Admin | Full access including settings and sharing |
The container creator automatically gets admin permission. Organization owners and admins can see all containers for billing and usage purposes, but need an explicit grant to edit containers they didn’t create. Managing a container’s grants is narrower still: it takes an admin grant on that container, or being its creator, or being an organization owner.
Containers with no individual creator
Section titled “Containers with no individual creator”A container that one of your organization’s own agents created with an organization API key (provision mode) belongs to the organization instead of to a person. Because there is no creator to be private to, access is decided by organization role alone:
| Role | Access to a provision-mode container |
|---|---|
| Owner | Admin: read, write, and manage settings, sharing, and deletion |
| Admin | Admin: read, write, and manage settings, sharing, and deletion |
| Member | Viewer: read its contents, no changes |
No grant is involved, and nobody has to share the container for a member to see it. Every member of the organization gets read access from the moment the container is created. These containers are listed under a Provisioned tab on the Containers page, attributed to the agent that created them.
This is the one case where a container is readable across the whole organization without being explicitly shared. Containers a person creates stay private to that person until they share them.
See Sharing Containers for a step-by-step guide.
Inviting Members
Section titled “Inviting Members”- Go to Organization Settings
- Click Members
- Click Invite Member
- Enter email and select role
- Click Send Invitation
The invited user will receive an email with a link to join your organization.
Changing Roles
Section titled “Changing Roles”- Go to Organization Settings → Members
- Find the member
- Click on their current role
- Select the new role
Removing Members
Section titled “Removing Members”- Go to Organization Settings → Members
- Find the member
- Click Remove
- Confirm removal
Removing a member immediately revokes their access to all containers in the organization.