Skip to main content

Roles and permissions

ZeaLLM has three role axes. Reviewer rights are derived — you can approve a key request if you are a platform admin, an org admin of that org, or a team admin of that team.

Platform roles​

RoleWriteScope
ADMINYesEntire platform
ADMIN_VIEWERNoEntire platform (oversight)
USERYesOwn keys, plus teams you belong to
USER_VIEWERNoSame visibility as USER

View-only roles see the matching sidebar but every mutation returns Your role is view-only.

Organization roles​

RoleEffect
ORG_ADMINTeam-admin rights for every team in the org; manage org profile and members
ORG_MEMBERMembership only — no extra approvals

Team roles​

RoleEffect
TEAM_ADMINApprove that team's key requests; manage members, apps and team keys
TEAM_MEMBERRequest keys against the team; see team context

Who sees which sidebar​

Sidebar itemsDeveloperTeam adminOrg adminPlatform admin
Workspace, Build & monitor, Measure & optimize, and Budgets … Customers under Cost managementYesYesYesYes
FinOps Attribution, Cost Events—ListedListedYes
ApprovalsOnly if a governance approverYesYesYes
Spend Governance, Teams—YesYesYes
Organizations——OwnAll
Users, Access & Tiers, Audit———Yes

Chargeback, Cost Centers, FinOps Attribution and Cost Events open only for platform admins, even where they are listed. Teams lists the teams you belong to, plus every team in your organizations for org admins. Navigating the portal describes every item.

Step-by-step operating guides: Developer, Team admin, Org admin, Platform admin, View-only.