Roles & Access
Who can do what inside an organization.
Organization roles
Every user has a role within each organization they belong to — a single account can belong to multiple organizations, with a different role in each.
Prop
Type
Invite teammates from Settings → Members; each invite specifies the role they'll have once accepted. See Organization Settings for everything else that lives under Settings.
Staff
Vulnix staff access is a completely separate flag — not a rung on the organization role ladder above. Staff sign in through a distinct portal with mandatory two-factor authentication and no grace period, and every staff action is audit-logged.
Demo access
Prospective customers get a read-only tour of a fixed, pre-seeded demo organization: every mutation is blocked centrally except a small allowlist of safe actions (like adding a test domain), so the demo can be explored freely without any risk of altering real seeded data.