Institution roles and permissions

Assign the least-privileged role that fits each person's worksheet, administration, or API work.

Who this is for
Institution administrators and members checking their access
Before you begin
  • An institution membership

Current role matrix

Institution capabilities by role
CapabilityAdministratorDeveloperEducator
Use an institution worksheet seatYesNoYes
Manage members and seatsYesNoNo
View admin billingYesNoNo
Create or revoke organization API keysYesYesNo
Buy organization API creditsYesYesNo
Create or revoke embedsYesYesNo
Edit API output brandingYesNoNo

Choose the least-privileged role

  • Administrator: manages organization membership, seat billing, API output branding, and all organization API resources.
  • Educator: creates worksheets using a purchased institution seat; does not manage billing or API resources.
  • Developer: manages shared organization keys, credits, usage, and embeds; does not receive a worksheet seat and cannot edit branding.

Change or remove access

  1. An administrator opens the organization profile on the Institution page.
  2. Review the person's current responsibilities before changing the role.
  3. Apply the new role and ask the member to switch away and back to refresh the active organization session.
  4. When removing a developer, rotate any shared API key they may have accessed.
  5. Before removing an admin, verify another current admin can manage the organization and billing.

Common assignments

  • A classroom teacher who prints worksheets: Educator.
  • An engineer integrating worksheets into an LMS: Developer.
  • A school operations lead who pays and invites members: Administrator.
  • A person who both administers and integrates: Administrator; do not add a broader duplicate role.

Success check

Every member has only the capabilities needed for current work, at least one current admin remains, and departing developers trigger key rotation.