5. Users & Roles
Control who can access, edit, and manage your workspace.
5.1 The Three Roles
Metaustral uses a three-level role system. Every user in a workspace is assigned exactly one role:
| Role | Who it is for | Typical use |
|---|---|---|
| Admin | Workspace owners and IT leads | Full control: users, connections, all assets, billing |
| Editor | Data stewards and analysts | Create, edit, and delete assets; manage playbooks and glossary |
| Viewer | Business users and stakeholders | Read-only: browse the catalog, search, view details |
5.2 Permissions by Role
| Action | Admin | Editor | Viewer |
|---|---|---|---|
| Browse & search the catalog | ✓ | ✓ | ✓ |
| View asset details | ✓ | ✓ | ✓ |
| AI Usage | ✓ | ✓ | ✓ |
| Create & edit data assets | ✓ | ✓ | — |
| Delete data assets | ✓ | ✓ | — |
| Manage Playbooks & Glossary | ✓ | ✓ | — |
| Add & manage database connections | ✓ | ✓ | — |
| Run imports & scheduled syncs | ✓ | ✓ | — |
| Invite & manage users | ✓ | — | — |
| View audit history | ✓ | — | — |
| Access billing & plan settings | ✓ | — | — |
5.3 Inviting Users
Only Admins can invite new users. To add a team member:
- Go to Admin panel → Users.
- Click New User.
- Enter the user's email address and select their role (Admin, Editor, or Viewer).
- Click Send invitation. The user receives an email with a link to set their password and join the workspace.
User limits by plan
Free: 1 admin (no additional users). Starter: up to 3 users. Pro: up to 30 users. Business: unlimited. See pricing →
5.4 Changing a User's Role
Admins can change any user's role at any time without removing and re-inviting them:
- Go to Admin panel → Users.
- Find the user and click Edit.
- Select the new role and save. The change takes effect immediately on their next action.
There must always be at least one Admin
You cannot remove or downgrade the last Admin in a workspace. Assign another Admin first if you need to change your own role.
5.5 Removing a User
To remove a user from the workspace, go to Admin panel → Users, find the user, and click Remove. The user immediately loses access. Any assets or playbooks they created remain in the catalog — ownership is not transferred automatically.