Roles and Permissions

Applicable roles: Organization (top-level user), Sub-user Last updated: 2026-07-14

This document uses comparison tables to clarify what each role can and cannot do, helping you decide "whether this task should be handled by the organization, the sub-user, or requires contacting the platform."

For the conceptual background of the account system, see Account System Overview.


1. Role Definitions

Role One-line description
Organization (top-level user) Enterprise account; manages the organization's balance, sub-users, Keys, and usage
Sub-user Caller; manages their own Keys and usage

Platform-level configuration (model listing, pricing, organization activation, etc.) is handled uniformly by the official platform and does not belong to the user roles within the console.

The sidebar after an organization logs in (10 menu items):

Organization view

The sidebar after a sub-user logs in (5 menu items):

Sub-user view


2. Permission Comparison Table

✅ Can operate | -- No permission | 🔸 Limited to own organization/self scope

Account and Organization

Capability Organization Sub-user
Create/edit/deactivate sub-users ✅ 🔸 --
Set sub-user business identity (username/delivery email) ✅ 🔸 --
Edit own profile ✅ 🔸

Activation and deactivation of organization accounts is handled by the official platform; please contact the platform if needed.

Funds and Quotas

Capability Organization Sub-user
Online top-up / redemption code top-up ✅ 🔸 --
Set quota limits for sub-users ✅ 🔸 --
Refunds -- (contact the platform) --
Download payment receipts / request invoices ✅ 🔸 --
View organization balance transactions ✅ 🔸 --
View own usage ✅ 🔸

Keys and Calls

Capability Organization Sub-user
Create API Key ✅ 🔸
Configure Key routing groups and advanced allowlists ✅ 🔸 🔸 (own Keys, routing groups only)
Set IP restrictions for Keys ✅ 🔸 🔸 (own Keys)
View the "Call Guide" ✅ 🔸
Call models ✅ 🔸

Platform Configuration

The following items are configured uniformly by the official platform. Neither organizations nor sub-users can operate them in the console. If adjustments are needed, please contact the platform:

  • Organization-level concurrency limit
  • Range of models available to the organization
  • Model launch / model pricing adjustments

3. Which Tasks Require Contacting the Platform

As an organization, you do not have permission to complete the following operations on your own and must contact the platform:

Item Why What to do
Increase organization concurrency limit Involves platform resource allocation Contact the platform to adjust the limit; see Concurrency Settings
Adjust the range of available models Platform-level resource control Configured uniformly by the platform; see Regions and Model Range
Refunds Involves financial security Contact the platform and provide the order number
Launch new models / adjust model pricing Platform operational decision Watch for system announcements

4. The Organization's "Dual Identity"

The organization (top-level user) is itself both a "manager" and a "caller": it can manage sub-users and set quotas, and it can also create its own Keys to call models. Note two points:

  • Quotas are for sub-users: quota limits are set for sub-users; the organization's own consumption is drawn directly from the organization balance.
  • Cannot deactivate/delete itself: to change the account entity, please contact the platform.

5. About Key Management for Sub-users

  • Sub-users create Keys themselves: sub-users can self-service create multiple Keys on the "API Keys" page, each independently named and optionally bound to a routing group (selectable only within the scope authorized by the organization), subject to quota limits; the organization can also create and distribute them on their behalf. See Sub-user Management for details.
  • How to restrict sub-users: you can restrict a sub-user's calls by deactivating the sub-user account or by lowering/exhausting their quota limit (when the quota is exhausted, all Keys under their name are rejected together).

6. v1 → v2 Role Naming Comparison

Old name New name Capability changes
Tenant / Tenant admin Organization (top-level user) Largely inherited, with added sub-user business identity, default routing configuration, Key routing groups (optional), and advanced allowlists (once group identifiers are enabled)
Regular member Sub-user Menu streamlined to 5 items; can self-service create Keys (limited to authorized groups)