Skip to main content

Understanding Roles and Access Levels in Tofu

Tofu has five roles that control what each member can see and do. Use this quick-reference matrix to pick the right role for a team member or client.

C
Written by Cristina Michelini

Quick Reference

Role

Best for

Billing

Runs the org (members + settings)

Entity scope

Create entities

Does the work (extract / validate / KB)

Owner

The account holder

All entities

Admin

Practice lead / ops manager

All entities

Billing

Finance / accounts person

Assigned only

Contributor

Internal team member

All entities

Collaborator

Client / limited user

Assigned only

In one line each

Owner: Everything, including the bill. The account holder.
Admin: Everything operational, but no billing access.
Billing: Pays the bill and works on assigned entities, nothing org-wide.
Contributor: Works across all entities and can create new ones, but cannot invite members.
Collaborator: Works on assigned entities only. Cannot create entities and invite members.

📌 Note: Billing and Collaborator members are assigned to each entity as either a Manager (can work on files and entity settings) or a Viewer (view only). "Does the work" applies when they are assigned as a Manager. You choose this when assigning them to an entity.


Detailed Permissions

For most teams, the quick reference above is all you need. The tables below cover the fine print.

Legend:

✔ has access

✖ no access

View = view only

Modify = can add, edit, or delete

Full = Collect, Extract, Validate, and Refine

KB = Knowledge Base and Tofie AI

Organization Summary page

Role

Billing info

Needs Review

Recent Activities

Extraction Statistics

Owner

Admin

Contributor

Collaborator

Billing

📌 Note: Contributors and Collaborators do not see billing-related information on the Summary page, including credit usage, the subscription progress bar, and the Go to Billing button. This ensures clients or sub-team members added to your organization aren't exposed to subscription or credit details.


Organization Settings page

Role

General Tab

Members Tab

Entity Roles Tab

Billing Tab

Features Tab

Owner

Can rename organization

Modify

View

Full access (view, subscribe, add card)

Full access

Admin

View

Modify

View

Contributor

View

View

View

Collaborator

View

View

View

Billing

View

View

View

Full access (view, subscribe, add card)


Entity level

Owner and Admin have full access to every entity: create, delete, entity info, members, connected apps, Knowledge Base, and all file actions.

Contributors can access all entities and create new ones, but cannot invite members.

Billing and Collaborator members only see entities they are assigned to. Their access inside each entity depends on whether they are assigned as a Manager or a Viewer:

Permission

Manager

Viewer

Create entity

Delete entity

Entity info

Modify

Members

Modify (limited)

View

Connected apps

Modify

View

Knowledge Base

Modify

View

File actions

Full

Limited

Did this answer your question?