Access control
Organization roles, project access, and two-factor authentication in Sazabi.
Access in Sazabi is governed by an organization role on each member, plus project access for restricted projects. Two-factor authentication protects each individual account. This page explains what each role can do.
Organization roles
Every member holds one of four roles. Each higher role includes everything the lower roles can do:
| Role | Can do |
|---|---|
| Owner | Everything, including renaming and deleting the organization. |
| Admin | Everything an owner can do, except organization rename and delete. Manages members, billing, integrations, and settings. |
| Member | Day-to-day work: connect log sources, configure MCP connectors and sandbox CLIs, and work with issues. Cannot manage members, billing, or organization settings. |
| Viewer | Read-only access. Not currently assignable from the dashboard — invited members are Admin or Member. |
Assign roles under Settings > Members. Managing members requires admin or owner; only an owner can transfer ownership.
How roles show up in the dashboard
Sazabi shows every control to every role who can reach a page. When your role cannot perform an action, the control is present but disabled, with a tooltip explaining what role you need — controls are never hidden by role. A page you can read but not change renders read-only rather than disappearing.
Project access
By default, every member can reach every project in the organization. A project can be restricted so that only specified members have access; manage this under Settings > Access on the project. Restricted projects do not appear to members without access.
Two-factor authentication
Two-factor authentication is a personal account setting, not an organization role. Each member enables it under Settings > Security. It adds a second factor to sign-in and is independent of the member's organization role.