Roles Overview
Every user has a user type, and — for the main operational type,
Member — an optional discipline (Dev/Testing/PO/UX) and, per space, a
level (member or lead). Cloud deployments add one more, separate
dimension on top: Super Admin, a platform-level operator role that
manages the whole SpecBridge Cloud account, not any single organization's
day-to-day work.
Admin
An organization-level administrator (not to be confused with a Super Admin — see below). Has full access within their tenant:
- Manage tenants, spaces, projects, and members
- Manage users: approve/reject pending registrations, activate/deactivate/ delete accounts, change roles
- Full read/write access to specs, the board, and the constitution
- View AI usage and (Cloud only) the organization's billing
Tenant Owner
A Member with ownership of their tenant (usually whoever created it).
Everything a regular Member can do, plus:
- Invite new members
- Add and remove tenant members, promote/demote
Member
The core operational role. Every Member has a discipline:
| Discipline | Focus |
|---|---|
| Dev | Implements specs |
| Testing | Validates specs and implementations |
| PO (Product Owner) | Manages the backlog, transfers specs between spaces |
| UX | Designs the user experience for a spec |
All disciplines share the same baseline permissions — create/manage specs, publish versions, transition status, update stage plans, work the board — the discipline mainly shapes which AI-assistant guidance and workflow prompts you see, not a hard permission wall.
Space-level Lead
Within a given space, a Member can additionally be promoted to Lead — elevated authority scoped to that one space, on top of their base discipline permissions.
Management
A read-only reporting role: can view specs, the board, and reports, but cannot create, edit, or transition anything.
Stakeholder
Also read-only, scoped to specs and the board — for external or lightweight observers who need visibility without write access.
Super Admin (Cloud only)
A platform-level operator account, entirely separate from any
organization's own roles above — a Super Admin isn't necessarily a member
of any organization at all. From the Super Admin platform (/super-admin)
they can view and manage every organization on SpecBridge Cloud: activate/
suspend accounts, change plan tiers, extend trials, view platform-wide
billing and audit logs, and (read-only) impersonate an organization to help
debug an issue. This role doesn't exist on self-hosted (Enterprise)
deployments — there's no cross-organization platform to administer.