- Organization roles — who can do what inside your own organization.
- Partner roles — for organizations that manage other organizations on their clients’ behalf.
Organization roles
Everyone in your organization holds exactly one role.
Manage these from Manage → Members.
Two rules protect the organization from being taken over or locked out:
- Only an Owner can change another Owner or Admin. An Admin can manage Members, but not their peers.
- An organization always has at least one Owner. The last Owner cannot be removed or demoted — transfer ownership first.
Partner roles
A partner is an organization that manages other organizations — an agency, a consultancy, a reseller. A partner is a normal Oxygen organization. It has its own workspaces, its own data, its own bill, and its own people. It simply also has permission to administer its clients’ organizations.Your client’s organization stays theirs. A partner administers it; it does not
own it. Client Owners keep full control of their own organization, and a partner can
never remove or demote a client’s Owner.
Two things decide what a partner’s person can do
1. What Oxygen allows the partner at all — the ceiling. When Oxygen sets up a partnership, it grants the partner a set of permissions. This is the maximum the partner can ever have. A partner cannot raise its own ceiling. 2. What role their admin gives them — within that ceiling. Inside the ceiling, the partner’s own admin assigns each person a role and decides which clients that person handles.Which clients a person handles
Each partner person is either:- Assigned to specific clients — they can only reach those organizations, or
- Unassigned — they can reach every client the partner manages.
Publishing apps vs. reading data
These are separate permissions, on purpose.
A partner can be allowed to publish and manage apps without being able to read
the underlying data. If a partner needs to build apps against your data, Oxygen must
grant App data access explicitly — it is off by default.