Roles and Permissions
Applicable roles: Organization (top-level user), Sub-user Last updated: 2026-07-14
This document uses comparison tables to clarify what each role can and cannot do, helping you decide "whether this task should be handled by the organization, the sub-user, or requires contacting the platform."
For the conceptual background of the account system, see Account System Overview.
1. Role Definitions
| Role | One-line description |
|---|---|
| Organization (top-level user) | Enterprise account; manages the organization's balance, sub-users, Keys, and usage |
| Sub-user | Caller; manages their own Keys and usage |
Platform-level configuration (model listing, pricing, organization activation, etc.) is handled uniformly by the official platform and does not belong to the user roles within the console.
The sidebar after an organization logs in (10 menu items):

The sidebar after a sub-user logs in (5 menu items):

2. Permission Comparison Table
✅ Can operate | -- No permission | 🔸 Limited to own organization/self scope
Account and Organization
| Capability | Organization | Sub-user |
|---|---|---|
| Create/edit/deactivate sub-users | ✅ 🔸 | -- |
| Set sub-user business identity (username/delivery email) | ✅ 🔸 | -- |
| Edit own profile | ✅ | ✅ 🔸 |
Activation and deactivation of organization accounts is handled by the official platform; please contact the platform if needed.
Funds and Quotas
| Capability | Organization | Sub-user |
|---|---|---|
| Online top-up / redemption code top-up | ✅ 🔸 | -- |
| Set quota limits for sub-users | ✅ 🔸 | -- |
| Refunds | -- (contact the platform) | -- |
| Download payment receipts / request invoices | ✅ 🔸 | -- |
| View organization balance transactions | ✅ 🔸 | -- |
| View own usage | ✅ | ✅ 🔸 |
Keys and Calls
| Capability | Organization | Sub-user |
|---|---|---|
| Create API Key | ✅ | ✅ 🔸 |
| Configure Key routing groups and advanced allowlists | ✅ 🔸 | 🔸 (own Keys, routing groups only) |
| Set IP restrictions for Keys | ✅ 🔸 | 🔸 (own Keys) |
| View the "Call Guide" | ✅ | ✅ 🔸 |
| Call models | ✅ | ✅ 🔸 |
Platform Configuration
The following items are configured uniformly by the official platform. Neither organizations nor sub-users can operate them in the console. If adjustments are needed, please contact the platform:
- Organization-level concurrency limit
- Range of models available to the organization
- Model launch / model pricing adjustments
3. Which Tasks Require Contacting the Platform
As an organization, you do not have permission to complete the following operations on your own and must contact the platform:
| Item | Why | What to do |
|---|---|---|
| Increase organization concurrency limit | Involves platform resource allocation | Contact the platform to adjust the limit; see Concurrency Settings |
| Adjust the range of available models | Platform-level resource control | Configured uniformly by the platform; see Regions and Model Range |
| Refunds | Involves financial security | Contact the platform and provide the order number |
| Launch new models / adjust model pricing | Platform operational decision | Watch for system announcements |
4. The Organization's "Dual Identity"
The organization (top-level user) is itself both a "manager" and a "caller": it can manage sub-users and set quotas, and it can also create its own Keys to call models. Note two points:
- Quotas are for sub-users: quota limits are set for sub-users; the organization's own consumption is drawn directly from the organization balance.
- Cannot deactivate/delete itself: to change the account entity, please contact the platform.
5. About Key Management for Sub-users
- Sub-users create Keys themselves: sub-users can self-service create multiple Keys on the "API Keys" page, each independently named and optionally bound to a routing group (selectable only within the scope authorized by the organization), subject to quota limits; the organization can also create and distribute them on their behalf. See Sub-user Management for details.
- How to restrict sub-users: you can restrict a sub-user's calls by deactivating the sub-user account or by lowering/exhausting their quota limit (when the quota is exhausted, all Keys under their name are rejected together).
6. v1 → v2 Role Naming Comparison
| Old name | New name | Capability changes |
|---|---|---|
| Tenant / Tenant admin | Organization (top-level user) | Largely inherited, with added sub-user business identity, default routing configuration, Key routing groups (optional), and advanced allowlists (once group identifiers are enabled) |
| Regular member | Sub-user | Menu streamlined to 5 items; can self-service create Keys (limited to authorized groups) |
