Skip to main content
Use roles and access levels together when you need to decide what someone can do in a workspace and on a specific shared resource.

Organization roles

Runway roles are strictly hierarchical: Owner > Admin > Manager > Member > Guest > Anonymous user. A user’s role caps what per-resource access can grant.
RoleProduct description
OwnerNo product description encoded.
AdminCan configure the model, workspace settings, and all workspace info.
ManagerCan trace and edit models, create scenarios, and access shared information in the workspace.
MemberCan trace models, create scenarios, and access shared information in the workspace.
GuestCan view pages and data that have been shared with them.
Anonymous userNo product description encoded.

Default capability matrix

This matrix shows the default system ACLs seeded for each role. A check means the default ACL grants that capability; a dash means it is not granted by the default ACL or is explicitly denied.
CapabilityOwnerAdminManagerMemberGuestAnonymous user
All resources - Full access
Scenario resources - Can merge
Integration - Full access
Integration query - Full access
Integration schema - Full access
Integration table - Full access
Integration table column - Full access
Dimension - Can view
Dimension - Can create
Dimension - Can edit
Section - Can delete
Unlisted drivers - Full access
Access control - Full access
Entity anonymization - Full access
Scenario - Full access
Scenario (default layer) - Can view
Scenario - Can create
Integration - Can create
Database column - Full access
External driver - Full access
Database lookups - Full access
All resources - Can create
Search - Full access
Guest and Anonymous user have no default ACLs; they only receive access that is explicitly shared.

Resource access levels

Resource typeAccess levelDescription
PagesFull accessCan edit, delete, and share the page.
PagesCan editCan edit page content, but not share or delete the page.
PagesCan viewCan view the page but can not edit or add other users.
PagesNo accessCannot view or access the page.
SectionsFull accessCan edit, delete, and share this section.
SectionsCan viewCan view this section and its contents.
SectionsNo accessCannot view this section.
BlocksFull accessCan edit, delete, and share this block.
BlocksCan viewCan view this block and its contents.
BlocksCan drill inAllow people to drill in to see the inputs for a given row.
BlocksNo accessCannot view this block.
ScenariosFull accessCan edit, delete, merge, and share this scenario.
ScenariosCan viewCan view this scenario.
ScenariosCan mergeAllow people to merge this scenario.
ScenariosNo accessCannot view this scenario.
Database columnsCan viewCan view this column’s data.
Database columnsNo accessCannot view this column’s data.
Role and resource access combine by taking the narrower result: the role sets the user’s maximum workspace capability, and the resource access level controls what they can do on a specific page, section, block, scenario, or database column.

What’s next