Roles and permissions

See what Admins, Members, and Managers can see and do in Tokenize, and how each role is assigned.

What you see in Tokenize depends on your role. Admins see the whole organization and manage settings. Members see their own usage. Managers are members who can also manage team settings for the people who report to them.

The roles

Admin. Sees organization-wide usage and manages the workspace: providers, API keys, devices, integrations, directory sync, privacy, budgets, models, MCP servers, and alerts. The person who creates the workspace is its first Admin. Admins land on the organization Overview when they sign in.

Member. Sees their own usage, sessions, and guidance, and can enroll their own computers. Members land on My Usage when they sign in. They don't see other people's usage or organization-wide totals.

Manager. Not a role you assign. A Member becomes a Manager automatically when your directory shows they have at least one direct report. Tokenize reads manager relationships from your identity provider through directory sync. A Manager can do everything a Member can, plus manage team budgets, team guidance, and team skills, and see alert history, for their reporting line (their direct reports and everyone below them). If their last report leaves, they lose that access.

You assign Admin or Member in Settings → Organization → Members. See Invite your team.

What each role sees

PageAdminManagerMember
OverviewWhole organization——
SessionsEveryone, with team and user filters, including Top CostTheir ownTheir own
UsersEveryone——
EngineeringYes——
Platform UsageYes——
AlertsView and manageAlert history for their teams—
OpportunitiesYes——
SkillsView and manageManage skills for their teams—
PluginsYes——
GuidanceOrganization and any teamTheir teams and their ownTheir own
BudgetsView, and set any team's budgetView, and set budgets within their reporting lineView
ModelsView and manageViewView
MCP ServersOrganization view, and manageTheir own viewTheir own view
My UsageYesYesYes

Settings by role

Settings tabAdminManager and Member
AccountYesYes
OrganizationManage members and invitationsView
DownloadsYes, including MDM DeploymentYes
My devicesYesYes
API keys, Providers, Provider aliases, Integrations, Directory Sync, PrivacyYes—

If you open a page your role can't reach, Tokenize sends you to My Usage.

Change someone's role

  1. Go to Settings → Organization and open the Members tab.
  2. Find the person and change their role to Admin or Member.

The change applies the next time their session refreshes. To make someone a Manager, update their manager relationship in your identity provider. It flows into Tokenize through directory sync.