Institution roles and permissions
Assign the least-privileged role that fits each person's worksheet, administration, or API work.
- Who this is for
- Institution administrators and members checking their access
- Before you begin
- An institution membership
Current role matrix
| Capability | Administrator | Developer | Educator |
|---|---|---|---|
| Use an institution worksheet seat | Yes | No | Yes |
| Manage members and seats | Yes | No | No |
| View admin billing | Yes | No | No |
| Create or revoke organization API keys | Yes | Yes | No |
| Buy organization API credits | Yes | Yes | No |
| Create or revoke embeds | Yes | Yes | No |
| Edit API output branding | Yes | No | No |
Choose the least-privileged role
- Administrator: manages organization membership, seat billing, API output branding, and all organization API resources.
- Educator: creates worksheets using a purchased institution seat; does not manage billing or API resources.
- Developer: manages shared organization keys, credits, usage, and embeds; does not receive a worksheet seat and cannot edit branding.
Change or remove access
- An administrator opens the organization profile on the Institution page.
- Review the person's current responsibilities before changing the role.
- Apply the new role and ask the member to switch away and back to refresh the active organization session.
- When removing a developer, rotate any shared API key they may have accessed.
- Before removing an admin, verify another current admin can manage the organization and billing.
Common assignments
- A classroom teacher who prints worksheets: Educator.
- An engineer integrating worksheets into an LMS: Developer.
- A school operations lead who pays and invites members: Administrator.
- A person who both administers and integrates: Administrator; do not add a broader duplicate role.
Success check
Every member has only the capabilities needed for current work, at least one current admin remains, and departing developers trigger key rotation.
