> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Project Roles

> Hand someone a project to run, let a team connect their own accounts, or give read-only access.

Apart from **Organization Admins**, a user can only reach a [project](/gateway/concepts/organizations-and-projects#projects) once they're given a role on it:

| Role | Access |
| - | - |
| **Project Admin** | Manage everything in the project: every linked account, API keys, webhooks, and who has access. |
| **Project Member** | Link their own accounts, and use and manage them. |
| **Project Viewer** | See how everything in the project is set up, without changing anything. |

<Note>
  **Organization Admins** act as **Project Admin** on every project, without being added to it.
</Note>

Add people to a project and choose their role in **Project Settings > Access**, or give a whole group a role with [Assign a group to a project](/secure/identity-and-access/roles-and-groups/groups#assign-a-group-to-a-project).

<Frame>
  <img src="https://mintcdn.com/stackone-60/p973ajpCTsOrQVNv/images/secure/identity-and-access/role-access/project-roles.svg?fit=max&auto=format&n=p973ajpCTsOrQVNv&q=85&s=b92c034b128e9b22d447156962fae09d" alt="Project roles shown for three users on Project 1. User A, the Project Admin, manages connector profiles and every linked account. User B, a Project Member, can link accounts through connector profiles, manages the account they linked, and has no access to the account User D linked. User C, a Project Viewer, can view connector profiles and every linked account. None of them can reach members and security settings or Project 2." width="1036" height="832" data-path="images/secure/identity-and-access/role-access/project-roles.svg" />
</Frame>

## What each role can do

| Resource | Project Admin | Project Member | Project Viewer |
| - | - | - | - |
| [Linked accounts](/gateway/concepts/linked-accounts) | Link, edit, re-authenticate, suspend, delete, and run requests against any account | Link their own accounts, then edit, delete, and run requests against those | View status and details |
| [Connector profiles](/gateway/concepts/connector-profiles) | Create, configure, scope actions and events, and delete | Create their own, which they then manage, and link accounts through shared ones | View authentication type and enabled actions of shared profiles |
| [Request logs](/connect/troubleshooting) | View | View for their own accounts and accounts shared with them | View |
| [API keys](/embed/api-keys) | Create, scope, and revoke | No access | No access |
| [Webhooks](/connect/webhooks) | Create, route events, and delete | No access | No access |
| Project settings | Manage all settings | No access | No access |

If [explicit account access](/secure/identity-and-access/roles-and-groups/overview#explicit-account-access) is enabled, a **Project Admin** can only view other people's accounts until granted a role on them.

## Related

<CardGroup cols={2}>
  <Card title="Who Can Grant Access" icon="robot" href="/connect/ai-platforms/overview#who-can-grant-access">
    Which accounts a Project Member can hand to an AI platform.
  </Card>

  <Card title="Connector Profile Access" icon="user-lock" href="/secure/identity-and-access/roles-and-groups/connector-profile-access">
    Limit who can link accounts through a sensitive connector profile.
  </Card>

  <Card title="Shared Accounts" icon="share-nodes" href="/secure/identity-and-access/roles-and-groups/shared-accounts">
    Let several people work through one linked account.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.