Roles & Permissions Reference
A complete reference of every role across organizations, teams, projects, and shared sessions.
This is your one-stop reference for every role in Kalima. Use the matrices below to see exactly who can do what across organizations, teams, projects, and shared sessions, so you can hand out access with confidence.
Kalima has four distinct permission areas, each with its own set of roles. They are independent of one another: someone can be an organization admin, a project viewer, and the owner of their own shared sessions all at the same time.
Organization roles
Organizations are shared containers for a company or group. They hold members, teams, and billing policies. Every organization has exactly one owner (the person who created it) and any number of admins, members, and viewers.
| Capability | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| View organization and member list | Yes | Yes | Yes | Yes |
| Invite and manage members | Yes | Yes | No | No |
| Change member roles | Yes | Yes | No | No |
| Suspend, reactivate, or remove members | Yes | Yes | No | No |
| Create and manage teams | Yes | Yes | No | No |
| Configure billing policy and top up balances | Yes | Yes | No | No |
| Edit organization name, slug, description, and logo | Yes | Yes | No | No |
| Transfer ownership | Yes | No | No | No |
| Delete the organization | Yes | No | No | No |
| Leave the organization | No | Yes | Yes | Yes |
| Counts as a billable seat | Yes | Yes | Yes | No |
The owner cannot be removed, and only the owner can transfer ownership or change another person's owner status. To wind down or hand over an organization, the owner must transfer ownership first. The viewer role is read-only (it can see the member list) and does not consume a billable seat.
What each organization role is for
Team roles
Teams live inside an organization and sub-divide it into groups, for example Sales and Support, each able to carry its own billing policy. Team membership uses two roles: lead and member.
| Capability | Team lead | Team member |
|---|---|---|
| Belong to the team and be a target for team sharing | Yes | Yes |
| Recognized as a team contact / coordinator | Yes | No |
Creating, renaming, recoloring, or deleting a team, and assigning who belongs to it, is an organization action handled by the org owner or an admin from the Teams tab. The team lead and member roles describe a person's place inside a team, not their power to manage the organization. Deleting a team marks it inactive rather than erasing it.
Project roles
Projects are folders that group sessions and share default transcription settings, and they can be shared with collaborators. Every project has an implicit owner (its creator) plus any collaborators you invite as admin, editor, or viewer.
| Capability | Owner | Admin | Editor | Viewer |
|---|---|---|---|---|
| View the project and its sessions | Yes | Yes | Yes | Yes |
| Create sessions in the project | Yes | Yes | Yes | No |
| Edit project default settings | Yes | Yes | Yes | No |
| Reset diverged sessions to defaults | Yes | Yes | Yes | No |
| Invite and manage collaborators | Yes | Yes | No | No |
| Change or remove other admins | Yes | No | No | No |
| Delete the project | Yes | No | No | No |
| Leave the project | No | Yes | Yes | Yes |
A handy way to remember it: viewers read, editors work (create sessions, change settings), admins manage people, and the owner controls everyone, including who else gets to be an admin.
Project collaboration rules
A few guardrails apply when you invite people to a project:
- Only the project owner can add, change, or remove other admins.
- You cannot change your own role.
- You cannot invite yourself or the project owner, and a duplicate pending invite for the same email is blocked.
- Invitations expire after 7 days, and an invite must be accepted from the exact email address it was sent to.
Learn the full workflow on the Projects page.
Session share grants
Sharing a single session is separate from project and organization membership. The session owner turns sharing on and then adds one or more grants that decide who may open the link. Each grant can carry its own optional expiry, and you can combine them.
| Grant type | Who gets in | Sign-in required |
|---|---|---|
| Public | Anyone who has the link | No |
| Authenticated | Any signed-in Kalima user | Yes |
| Specific user | One person, matched by their account email | Yes |
| Organization | All active members of a chosen organization | Yes |
| Team | All members of a chosen team | Yes |
When you first enable sharing, Kalima creates a default authenticated grant, so the link requires sign-in until you add other grants. If you mix an authenticated grant with specific-user, organization, or team grants, signing in becomes a prerequisite and only the specific grants decide who actually gets in. Add a public grant for a fully open link.
What viewers can and cannot do
A shared session is read-only for everyone except the owner. Whatever grant let them in, viewers get the same experience:
- They can read the live or finished transcript, see translations, and play available audio.
- They can use AI chat and view a read-only AI summary if you share one.
- They cannot record, create sessions, edit the transcript, or change settings.
- They cannot see your other projects or workspaces, only the one session you shared.
Only the session owner can enable or disable sharing, set a password or expiry, manage grants, or invite viewers by email. Disabling a link instantly disconnects everyone currently watching; re-enabling it later restores the same URL. See Sharing a session and Live viewer mode for the full picture.
Seats and billing roles
Roles also affect what you pay. On seat-based plans, a seat is a billable membership slot.
Active organization owners, admins, and members each consume one seat; viewers never do. This makes the viewer role a good fit for stakeholders who only need to keep an eye on membership without participating. For how shared balances and funding order work, see Billing & seats.
Frequently asked questions
No, they are independent. The same person can be an organization member, a project editor, and the owner of their own shared sessions at once. Each area grants only the access defined for that role within that area.
Only the owner. Organization admins and project admins can manage almost everything else, but deleting the container, and transferring or changing ownership, is reserved for the owner. Deleting an organization is permanent and removes its data.
No. Editors can create sessions and edit project settings, but only the project owner or an admin can invite, change, or remove collaborators. And only the owner can manage other admins.
You cannot change your own role in a project or organization, this prevents you from accidentally locking yourself out of access you need. Ask the owner (or another admin, where allowed) to make the change.
No. Session sharing is free and not tied to seats. Likewise, the read-only organization viewer role does not consume a billable seat, only active owners, admins, and members do.
Organization and project collaboration invitations expire after 7 days. After that they're marked expired and you'll need to send a fresh one. The invite must be accepted from the exact email it was sent to.