Skip to main content

Understanding Roles and Access Levels in tofu

tofu has five roles that control what each member can see and do. Use this quick-reference matrix to pick the right role for a team member or client.

S
Written by SunTao

Quick Reference

Role

Best for

Billing

Runs the org (members + settings)

Entity scope

Create entities

Does the work (extract / validate / KB)

Owner

The account holder

All entities

Admin

Practice lead / ops manager

All entities

Billing

Finance / accounts person

Assigned only

Contributor

Internal team member

Assigned only

Collaborator

Client / limited user

Assigned only

In one line each

Owner: Everything, including the bill. The account holder.
Admin: Everything operational, but no billing access.
Billing: Pays the bill and works on assigned entities, nothing org-wide.
Contributor: Must be invited to an entity to see its documents, but can create new entities. Cannot manage members or billing.
Collaborator: Works on assigned entities only. Cannot create entities and invite members.

📌 Note: Billing and Collaborator members are assigned to each entity as either a Manager (can work on files and entity settings) or a Viewer (view only). "Does the work" applies when they are assigned as a Manager. You choose this when assigning them to an entity.


Detailed Permissions

For most teams, the quick reference above is all you need. The tables below cover the fine print.

Legend:

✔ has access

✖ no access

View = view only

Modify = can add, edit, or delete

Full = Collect, Extract, Validate, and Refine

KB = Knowledge Base and tofie AI

Organization Summary page

Role

Billing info

Needs Review

Recent Activities

Extraction Statistics

Owner

Admin

Contributor

Collaborator

Billing

📌 Note: Contributors and Collaborators do not see billing-related information on the Summary page, including credit usage, the subscription progress bar, and the Go to Billing button. This ensures clients or sub-team members added to your organization aren't exposed to subscription or credit details.


Organization Settings page

Role

General Tab

Members Tab

Entity Roles Tab

Billing Tab

Features Tab

Owner

Can rename organization

Modify

View

Full access (view, subscribe, add card)

Full access

Admin

View

Modify

View

Contributor

View

View

View

Collaborator

View

View

View

Billing

View

View

View

Full access (view, subscribe, add card)


Entity level

Owner and Admin have full access to every entity: create, delete, entity info, members, connected apps, Knowledge Base, and all file actions.

Contributors must be invited to an entity to see its documents, and can create new entities, but cannot manage members or billing.

Billing and Collaborator members only see entities they are assigned to. Their access inside each entity depends on whether they are assigned as a Manager, Uploader, or Viewer:

Capability

Manager

Uploader

Viewer

Upload documents

View documents and extracted data

Edit extracted data

Verify and unverify extractions

Export data

Delete extractions

Delete document pages

Manage integrations

Manage entity members

Edit entity knowledge and priority fields

Edit contact knowledge

Update entity settings

📌 Note:

  • Deleting document pages isn't available to any entity role — only Organization Owners and Admins can do this, since they have full access to every entity regardless of entity role. Plan limits can also further restrict uploading.

  • You can see this same breakdown without leaving the app — open Roles & Permissions to view Organization roles and Entity roles side by side.

Did this answer your question?