Roles and permissions
ZeaLLM has three role axes. Reviewer rights are derived — you can approve a key request if you are a platform admin, an org admin of that org, or a team admin of that team.
Platform roles
| Role | Write | Scope |
|---|---|---|
ADMIN | Yes | Entire platform |
ADMIN_VIEWER | No | Entire platform (oversight) |
USER | Yes | Own keys, plus teams you belong to |
USER_VIEWER | No | Same visibility as USER |
View-only roles see the matching sidebar but every mutation returns Your role is view-only.
Organization roles
| Role | Effect |
|---|---|
ORG_ADMIN | Team-admin rights for every team in the org; manage org profile and members |
ORG_MEMBER | Membership only — no extra approvals |
Team roles
| Role | Effect |
|---|---|
TEAM_ADMIN | Approve that team's key requests; manage members, apps and team keys |
TEAM_MEMBER | Request keys against the team; see team context |
Who sees which sidebar
| Sidebar items | Developer | Team admin | Org admin | Platform admin |
|---|---|---|---|---|
| Workspace, Build & monitor, Measure & optimize, and Budgets … Customers under Cost management | Yes | Yes | Yes | Yes |
| FinOps Attribution, Cost Events | — | Listed | Listed | Yes |
| Approvals | Only if a governance approver | Yes | Yes | Yes |
| Spend Governance, Teams | — | Yes | Yes | Yes |
| Organizations | — | — | Own | All |
| Users, Access & Tiers, Audit | — | — | — | Yes |
Chargeback, Cost Centers, FinOps Attribution and Cost Events open only for platform admins, even where they are listed. Teams lists the teams you belong to, plus every team in your organizations for org admins. Navigating the portal describes every item.
Step-by-step operating guides: Developer, Team admin, Org admin, Platform admin, View-only.