Two separate dials control what a person can do in Cando: their role in the organization, and which agents they’ve been granted. Keeping them separate is the point, so a member can have full use of one agent and no sight of another.

The roles

  • Member: works with the agents they’ve been granted, in full: chat, Agent Automations, connections, history
  • Admin: everything a member can do, plus running the organization: inviting and revoking members, renaming agents, seeing the full agent roster, and managing billing and usage
  • Owner: the admin who can also delete the organization. Every organization has one, and an owner counts as an admin everywhere

What needs which role

When something’s off-limits, the screen says so rather than hiding: non-admins can see who has access under Members, for instance, without being able to change it.

Agent access is a grant, not a role

Agents are granted to members individually, at invitation or later by sharing. A grant is the full agent; there are no per-agent roles. Two colleagues seeing entirely different agent lists is normal and deliberate: it’s how the finance agent stays with finance.