Skip to main content

Phala Cloud Workspace Roles

Last updated: August 5, 2026

A workspace has three roles: Owner, Admin, and Member.

The Owner is always the workspace creator — the person who created the workspace. Creator is not a fourth role. It is the fixed identity behind the Owner seat.

Roles control who can change people and money settings for the workspace. They do not limit day-to-day work on machines. A Member can create and run machines the same way an Admin can. What Members cannot do is open billing or invite and remove people.

For invoices and payments, see the Billing page.

Permission Matrix

CapabilityOwnerAdminMember
Is the workspace creatorYesNoNo
Create, manage, and delete machinesYesYesYes
Deploy and update appsYesYesYes
Manage webhooksYesYesYes
Place and view GPU rental ordersYesYesYes
Create and revoke own API tokens in the dashboardYesYesYes
View member listYesYesYes
Leave the workspaceNoYesYes
Can be removed by Admin or OwnerNoYesYes
Invite or remove membersYesYesNo
View and change billingYesYesNo
Change workspace name or URLYesNoNo
Change another member's roleYesNoNo
Role can be changed to Admin or MemberNoYesYes

What's the difference between Owner and Admin?

Almost nothing in day-to-day use. Admin and Owner can both manage machines, people, and billing.

Only the Owner can:

  • Change the workspace name or URL
  • Change another member's role between Admin and Member

The Owner is also the creator. That seat cannot move to someone else.

What is the creator?

The creator is the person who created the workspace. In Phala Cloud, the creator holds the Owner role.

Because creator identity is fixed:

  • Nobody can invite someone as Owner
  • Nobody can promote an Admin or Member to Owner
  • Nobody can remove the creator
  • The creator cannot leave the workspace
  • Nobody can change the creator's role

To give someone broad control without changing the creator seat, make them an Admin.

Can a Member create or delete machines?

Yes. Members can create, start, stop, resize, and delete machines. They can also deploy apps, manage webhooks, and place GPU rental orders.

Members cannot open billing or invite and remove people. If you need those, ask an Admin or the Owner.

Who can invite or remove people?

Only Admin and Owner.

They can:

  • Send email invitations as Admin or Member
  • Create an invite link (people who join through the link become Members)
  • Cancel pending invitations
  • Remove other members

Nobody can invite someone as Owner. Nobody can remove the creator or Owner.

If you need to add someone, ask an Admin or the Owner.

Who can view and change billing?

Only Admin and Owner.

They can view balances and invoices, manage payment methods, change billing settings, and add funds. Members never see billing pages.

If you need access to billing, ask an Admin or the Owner.

Can I make someone else the Owner?

No. Ownership stays with the workspace creator. You cannot invite someone as Owner, and you cannot promote an Admin or Member to Owner.

To give someone broad control without changing ownership, make them an Admin.

Can I leave a workspace?

Yes, if you are an Admin or a Member. Leaving removes your access and revokes your workspace API tokens.

No, if you are the Owner or creator. The creator cannot leave and cannot be removed.

Do I need Admin to use the API?

No. A Member can create a workspace API key in the dashboard and use it for machines, apps, webhooks, and GPU rentals.

Billing still needs an Admin or Owner signed in to the dashboard.

Can an API key manage billing?

No. API keys cannot read or change billing. They also cannot create, list, or revoke API tokens.

An API key only works in the workspace it was created in. Use it for automation on machines and apps. Manage billing and tokens in the dashboard while logged in.

What happens when someone is removed?

They lose workspace access right away. Their workspace API tokens for that workspace are revoked.

The creator cannot be removed. Everyone else can be invited again later if an Admin or Owner sends a new invitation.