Roles and permissions
The roles and permissions reference lists what a viewer, an editor and the owner can do in an Athenode project, and what a project token can do on a member's behalf.
A role belongs to one member in one project, so the same person can be the owner of one project and a viewer of another. The owner is the person who created the project. Editors and viewers are invited by the owner.
| Role | In one sentence |
|---|---|
| Viewer | Reads the project's specifications, agent setups, ToDo cards, members and plan. |
| Editor | Changes specifications, agent setups and ToDo cards, and connects an AI coding tool with a project token. |
| Owner | Does everything an editor does, and also deletes specifications, manages members, the plan and billing, and deletes the project. |
Specifications
A specification is one described piece of work, with a title, a summary, Markdown content, a status and its own questions and answers. Specifications describes them.
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Read specifications, their questions and answers, implementation plans and blockers | Yes | Yes | Yes |
| Search the specification tree | Yes | Yes | Yes |
| Create and edit a specification | No | Yes | Yes |
| Change a specification's status | No | Yes | Yes |
| Move a specification in the tree | No | Yes | Yes |
| Add and remove blockers | No | Yes | Yes |
| Add questions and record answers | No | Yes | Yes |
| Delete a specification with its sub-specifications | No | No | Yes |
Agent setups and the setup library
An agent setup is a named bundle of what your AI coding tools work with: skills, agents, rules, MCP servers and setup files. The setup library is the shared catalogue of agent setups that projects have published. Agent setups and the setup library describe them.
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Read the project's setups and everything in them | Yes | Yes | Yes |
| Browse the setup library and read its entries | Yes | Yes | Yes |
| Like a library entry | Yes | Yes | Yes |
| Create, clone, rename and delete a setup | No | Yes | Yes |
| Add, edit and remove skills, agents, MCP servers and setup files | No | Yes | Yes |
| Edit the rules | No | Yes | Yes |
| Import skills and update imported skills | No | Yes | Yes |
| Add a library entry as a new setup, or merge an entry into a setup | No | Yes | Yes |
| Update a setup from its library entry | No | Yes | Yes |
| Pull from another setup | No | Yes | Yes |
| Publish a setup, publish a new version, edit the entry and unpublish it | No | Yes | Yes |
Publishing also needs a paid plan: the project must be on the Solo, Team or Business plan. Pulling from a setup of another project needs the editor or owner role in the project you pull into and membership of the project you pull from.
ToDo cards
A ToDo card is a short note of work to do later: a follow-up, tech debt, a bug or an idea. ToDo cards describes them.
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Read cards and their open questions | Yes | Yes | Yes |
| Create, edit and delete a card | No | Yes | Yes |
| Change a card's status | No | Yes | Yes |
| Add, edit, answer and delete a card's open questions | No | Yes | Yes |
Project tokens
A project token is a personal access token that lets the Athenode CLI, and your AI agent through it, act on one project. Project tokens describes them.
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Create a project token | No | Yes | Yes |
| See your own tokens | No | Yes | Yes |
| See other members' tokens | No | No | Yes |
| Revoke your own token | No | Yes | Yes |
| Revoke another member's token | No | No | Yes |
A viewer cannot create a project token, so an editor or the owner connects the Athenode CLI and the AI agents.
Members
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| See the members list | Yes | Yes | Yes |
| See the email address of a pending invite | No | No | Yes |
| Invite a member | No | No | Yes |
| Change a member's role or the role of a pending invite | No | No | Yes |
| Cancel a pending invite | No | No | Yes |
| Remove a member | No | No | Yes |
| Leave the project | Yes | Yes | No |
Inviting needs the Team or Business plan. Invite and manage members has the steps.
Project, plan and billing
| Action | Viewer | Editor | Owner |
|---|---|---|---|
| Open the project | Yes | Yes | Yes |
| Rename the project | No | Yes | Yes |
| Delete the project | No | No | Yes |
| See the plan, the usage of each limit and the subscription details | Yes | Yes | Yes |
| Subscribe, upgrade, downgrade and cancel | No | No | Yes |
| Undo a scheduled plan change | No | No | Yes |
| Change the payment method and open invoices | No | No | Yes |
Billing and plan changes has the steps, and Plans and limits lists what each plan allows.
The owner role
A project has one owner, the person who created it. Every other member is an editor or a viewer, and the owner's role cannot be changed on the Users page.
Ownership passes to another member when the owner's Athenode account is deleted and the project has other members. The project passes to one of them: an editor before a viewer, and among members with the same role the one who joined first. The project moves to the Free plan at the same time. Your account describes account deletion.
What a project token can do
A project token acts as the member who created it, with the role that member has at that moment, in that one project. A token created by an editor can do what an editor can do in the tables for specifications, agent setups and the setup library. A token created by the owner can also delete a specification.
The following actions are done by a signed-in member in the web app, whichever member created the token:
- managing members and invites;
- creating, listing and revoking project tokens;
- seeing or changing the plan and billing;
- liking a library entry;
- changing anything in an Athenode account.
On ToDo cards a token does less than its member does in the web app. With a token, the Athenode CLI and your AI agent can create a card with up to 3 open questions, read cards, close an open card as done or dismissed, and answer a question that has no answer. Reopening, editing and deleting a card, and adding, editing and deleting questions on an existing card, are done in the web app.
How a role change affects project tokens
A token follows the member who created it.
- After a change from editor to viewer, the tokens that member created keep working and can only read. A viewer cannot see or revoke tokens, so the owner revokes them.
- After a change from viewer to editor, the member can create tokens.
- After a member is removed or leaves, the tokens that member created for the project stop working.