# Members and Roles

Invite teammates from **Admin > Members**. Each member gets a role, and some members can be restricted to specific workspaces.

## Roles

- Admin: manage organization settings, workspaces, members, and content.
- Editor: write and publish content in allowed workspaces.
- Viewer: read private content in allowed workspaces.
- Guest: read only the workspaces and pages assigned to them.
- Billing: manage billing without broad content administration.

## Workspace scope

Use restricted access when a member should only see part of the organization. A restricted member can only reach assigned workspaces. Cross-workspace access behaves like the workspace does not exist.

## Guests

Guests are useful for customers, contractors, and reviewers. Assign only the workspaces and articles they need.

## Invites

Invites carry role and scope. When a user accepts an invite, ContextOwl applies those permissions immediately.
