Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
123 changes: 19 additions & 104 deletions accounts-billing/manage-accounts.mdx
Original file line number Diff line number Diff line change
@@ -1,129 +1,44 @@
---

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the Coleman–Liau Index grade (14.12) below 9.

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the Flesch reading ease score (41.45) above 70.

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the LIX score (46.77) below 35.

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the Automated Readability Index (10.33) below 8.

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the Flesch–Kincaid grade level (10.32) below 8.

Check warning on line 1 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L1

Try to keep the SMOG grade (11.12) below 10.
title: "Manage accounts"
description: "Create accounts, manage teams, and configure user permissions in Runpod. Review account, billing, and management details for Runpod."
sidebarTitle: "Manage accounts"
description: "Learn about Runpod account types: personal accounts, teams, and organizations. Understand which account type fits your collaboration needs."
---

To access Runpod resources, you need to either create your own account or join an existing team through an invitation. This guide explains how to set up and manage accounts, teams, and user roles.
Runpod supports three account types: personal accounts, teams, and organizations. Choose the type that fits how you and your collaborators work.

## Create an account
## Personal accounts

Sign up for a Runpod account at [console.runpod.io/signup](https://www.console.runpod.io/signup).
A personal account is the default account type. Sign up at [console.runpod.io/signup](https://console.runpod.io/signup) to get started. All resources you deploy, including Pods, Serverless endpoints, and network volumes, belong to your personal account.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please keep an explicit ## Create an account heading here.

24 pages link to /accounts-billing/manage-accounts specifically as the signup prerequisite, for example:

The signup URL does survive inside this paragraph, so nothing 404s, but those readers arrive at an account-types explainer rather than instructions, and the #create-an-account anchor is gone. Re-adding the H2 preserves the anchor and fixes all 24 in one edit.

While here: docs.json:1683 redirects /docs/invites to this page, which existed to serve the invite content this PR moved. It should now point at the teams page. release-notes.mdx:432 links "Teams: ... role-based access control" here too, and wants the roles page.


Once created, you can use your account to deploy Pods, create Serverless endpoints, and access other Runpod services. Personal accounts can be converted to team accounts at any time to enable collaboration features.
## Teams

## Convert to a team account
Teams let multiple users collaborate under a shared account with role-based access control.

Team accounts enable multiple users to collaborate on projects and share resources.
For details on setting up and managing a team, see [Manage teams](/teams/manageteams).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

teams/teamroles is in the sidebar but nothing in the repo links to it in prose, so the only way to find it is scanning the nav. Worth linking from here, and from the invite step on the Manage teams page where a reader picks a role.

Suggested change
For details on setting up and managing a team, see [Manage teams](/teams/manageteams).
For details on setting up and managing a team, see [Manage teams](/teams/manageteams). For what each role can do, see [Roles and permissions](/teams/teamroles).


To convert your personal account into a team account:
## Organizations

1. Navigate to the [Team page](https://www.console.runpod.io/team) in the Runpod console.
2. Select **Convert to a Team Account**.
3. Enter a team name and confirm the conversion.
Organizations are provisioned accounts for companies and larger teams.

Check warning on line 21 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L21

In general, use active voice instead of passive voice ('are provisioned').

<Note>

You can revert your account back to a personal account at any time. To revert, scroll to the bottom of the [Team page](https://www.console.runpod.io/team) and select **Delete Team**.

</Note>

## Invite team members

Team accounts can invite new members to collaborate. Each invitation includes a specific role that determines the member's permissions.

<img src="https://promptless-customer-doc-assets.s3.amazonaws.com/docs-images/org_2tHD09rTU0IcE4clVjTuJCTn0an/create-team-invite-dialog-d8cb3fc6.png" alt="Create Team Invite dialog showing role selection and required email field" />

To invite a new member:

1. Navigate to the [Team page](https://www.console.runpod.io/team) in the Runpod console.
2. In the **Members** section, select **Invite New Member**.
3. Choose [the appropriate role](#roles-and-permissions) for the new member.
4. Enter the email address of the person you want to invite and click **Create Invite**.
5. Copy the generated invitation link from the **Pending Invites** section and share it with the person you want to invite.

Invitation links remain active until used or manually revoked. You can view all pending invitations in the team management interface.

## Join a team

When invited to join a team, you'll receive an invitation link from a team member. To accept:

1. Click the invitation link provided by the team member.
2. Select **Join Team** to accept the invitation.

Your account will gain access to the team's resources based on the role assigned to you.

## Roles and permissions

Runpod provides four distinct roles to control access within team accounts. Each role includes specific permissions designed for different responsibilities.

| Permission | Basic | Billing | Dev | Admin |
|------------|-------|---------|-----|-------|
| Access team account | ✅ | ✅ | ✅ | ✅ |
| Connect to existing Pods | ✅ | ❌ | ✅ | ✅ |
| Create/delete/start/stop Pods | ❌ | ❌ | ✅ | ✅ |
| Create/delete Serverless endpoints | ❌ | ❌ | ✅ | ✅ |
| Send requests to Serverless endpoints | ✅ | ❌ | ✅ | ✅ |
| Connect to existing Instant Clusters | ✅ | ❌ | ✅ | ✅ |
| Create/delete/start/stop Instant Clusters | ❌ | ❌ | ❌ | ✅ |
| Create/update/delete network volumes | ❌ | ❌ | ✅ | ✅ |
| View billing information | ❌ | ✅ | ❌ | ✅ |
| Manage payment methods | ❌ | ✅ | ❌ | ✅ |
| Invite team members | ❌ | ❌ | ❌ | ✅ |
| Manage team permissions | ❌ | ❌ | ❌ | ✅ |
| Modify team account settings | ❌ | ❌ | ❌ | ✅ |
| Access audit logs | ❌ | ❌ | ❌ | ✅ |

### Basic role

The basic role provides essential access for users who need to work with existing resources without management capabilities.

This role allows users to access the team account and connect to already-deployed computing resources (e.g., Pods and Serverless endpoints) for development work. Users with this role cannot view billing information, start or stop Pods, or create new resources.

### Billing role

The billing role focuses exclusively on financial management aspects of the account.

Users with this role can access all billing information, manage payment methods, and view invoices. They cannot access computing resources, making this role ideal for finance team members who need billing access without operational permissions.

### Dev role

The dev role extends basic permissions with additional capabilities for active development work.

This role includes all basic permissions plus the ability to start, stop, and create Pods. Developers can fully manage computing resources for their work while remaining restricted from billing information and account settings.

### Admin role

The admin role provides complete control over all account features and settings.

Administrators have unrestricted access to manage team members, configure account settings, handle billing, and control all team computing resources. This role should be reserved for team leaders and trusted members who need full account access.
For details on how organizations work, see [Organizations](/organizations/orgs-overview).

## Account spend limits

By default, Runpod accounts have a spend limit of \$80 per hour across all resources. This limit protects your account from unexpected charges. If your workload requires higher spending capacity, you can [contact support](https://www.runpod.io/contact) to increase it.
By default, Runpod accounts have a spend limit of $80 per hour across all resources. This protects your account from unexpected charges. To increase the limit, [contact support](https://www.runpod.io/contact).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The spend limit description overstates what is enforced, and the dollar-sign escape was dropped.

checkSpend sums costPerHr over Pods with desiredStatus: RUNNING and compares at deploy/resume time only (model/src/pod/util/checkSpend.ts:38-49). So:

  • storage and network volumes are not counted
  • already-running resources are never stopped, only new deploys are blocked
  • postpaid accounts bypass it entirely (checkSpend.ts:112, if (isPostpaid) return)

The 80 default itself is right (prisma/schema.prisma:420).

On the escape: the repo writes an escaped dollar sign in prose in 257 places, including pages that link here and escape it on adjacent lines. A lone dollar sign renders fine in Mintlify, so this is consistency rather than breakage.

Suggested rewrite: "By default, your account can run up to \$80 per hour of compute at once. Deploying or resuming a Pod or Serverless worker that would push your combined hourly rate above that limit is blocked. Storage is not counted toward the limit, and resources that are already running are unaffected. To increase the limit, contact support."


## Monitor account activity

Runpod provides comprehensive audit logs to track all actions performed within your account. This feature helps maintain security and accountability across team operations.
Runpod provides comprehensive audit logs to track all actions performed within your account. This feature helps maintain security and accountability across your operations.

Access audit logs at [console.runpod.io/user/audit-logs](https://www.console.runpod.io/user/audit-logs).
Access audit logs at [console.runpod.io/user/audit-logs](https://console.runpod.io/user/audit-logs).

The audit system records detailed information about each action, including the user who performed it, the affected resource, and the timestamp. You can filter logs by date range, user, resource type, resource ID, and specific actions to investigate account activity or troubleshoot issues.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The filter list does not match the API. AuditLogInput accepts ownerId, scope, actorIds, cursor, limit, startDate, endDate, search, actions (node/graphql/schema/auditLog.ts:41-51). There is no resource-type or resource-ID filter; resourceType and resourceId are display-only fields on the AuditLog type (:20-21).

The actor filter is also org-only: the "All users" selector renders only when scope is ORGANIZATION (components/AuditLogs/index.tsx:226), so it is not available on a personal or team account.

Suggested change
The audit system records detailed information about each action, including the user who performed it, the affected resource, and the timestamp. You can filter logs by date range, user, resource type, resource ID, and specific actions to investigate account activity or troubleshoot issues.
The audit system records detailed information about each action, including the user who performed it, the affected resource, and the timestamp. You can filter logs by date range, action, or free-text search to investigate account activity or troubleshoot issues. In an organization, admins and billing members can also filter by the user who performed the action.

Optional addition: logs export as CSV, JSON, or XML (index.tsx:275-295), which is currently undocumented anywhere.


Regular review of audit logs helps identify unusual activity and ensures team members use resources appropriately.

## Best practices

When managing team accounts, establish clear role assignments based on each member's responsibilities. Regularly review team membership and remove access for members who no longer need it.

For enhanced security, use the principle of least privilege by assigning the minimum role necessary for each team member's work. Consider creating separate accounts for billing management to isolate financial access from technical operations.

Monitor audit logs periodically to ensure compliance with your organization's policies and identify any unauthorized activities early.
Regular review of audit logs helps identify unusual activity and ensures resources are being used appropriately.

Check warning on line 37 in accounts-billing/manage-accounts.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

accounts-billing/manage-accounts.mdx#L37

In general, use active voice instead of passive voice ('being used').

## Next steps

After setting up your account and team you can:

* [Create API keys](/get-started/api-keys) to enable programmatic access to Runpod services.
* [Deploy your first Pod](/get-started) to start using GPU resources.
* Configure [Serverless endpoints](/serverless/overview) for scalable AI inference.
* Set up [billing and payment methods](https://console.runpod.io/user/billing) for your team.
- [Manage teams](/teams/manageteams) to invite members and assign roles.
- [Organizations](/organizations/orgs-overview) for enterprise billing and resource management.
- [Create API keys](/get-started/api-keys) for programmatic access to Runpod services.
- [Set up billing](/accounts-billing/billing) to manage payment methods and view usage.
7 changes: 7 additions & 0 deletions docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -287,6 +287,13 @@
"accounts-billing/add-tax-id"
]
},
{
"group": "Teams",
"pages": [
"teams/manageteams",
"teams/teamroles"
]
},
{
"group": "Organizations (Beta)",
"pages": [
Expand Down
63 changes: 63 additions & 0 deletions teams/manageteams.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
---

Check warning on line 1 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L1

Try to keep the Flesch reading ease score (52.84) above 70.

Check warning on line 1 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L1

Try to keep the LIX score (36.32) below 35.

Check warning on line 1 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L1

Try to keep the Flesch–Kincaid grade level (8.62) below 8.

Check warning on line 1 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L1

Try to keep the SMOG grade (10.76) below 10.

Check warning on line 1 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L1

Try to keep the Coleman–Liau Index grade (10.30) below 9.
title: "Manage teams"
sidebarTitle: "Manage teams"
description: "Create and manage team accounts in Runpod. Invite members, assign roles, and collaborate on Pods, endpoints, and other resources."

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Filename convention: manageteams.mdx and teamroles.mdx are the only multi-word action slugs in the repo without separators. 175 of 255 prose pages use kebab-case, and every immediate sibling does: accounts-billing/manage-accounts, add-tax-id, manage-payment-cards; organizations/orgs-overview, org-roles, orgs-billing.

Since slugs are permanent URLs, worth renaming to teams/manage-teams.mdx and teams/team-roles.mdx (or teams/roles.mdx, mirroring organizations/org-roles) before this ships. That also means updating docs.json:290-294 and the two links in accounts-billing/manage-accounts.mdx.

I noticed commit 1718ceae renamed teams.roles to teamroles, so this may have been deliberate. If there is a reason, ignore me.

---

Teams let multiple users collaborate on Runpod resources under a shared account. Any personal account can be converted to a team account to enable member management and role-based access control.

Check warning on line 7 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L7

In general, use active voice instead of passive voice ('be converted').

## Create a team account

<Steps>
<Step title="Open the Team page">
Navigate to **Create team** in the [Runpod console](https://console.runpod.io/team).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor: this step is titled "Open the Team page" but the body says to navigate to Create team. The second Steps block at line 29-30 says "Go to the Team page", which reads better. Both labels are real; the sidebar entry is "Create team" for a personal account and "Team" once you are on a team (routes.tsx:187-201). Worth making the title and body agree.

Also verified and correct as written: the Convert to a Team Account button and modal, the team display name field, and the acknowledgment checkbox, which does gate the confirm button.

Two undocumented limits you may want to mention: team names must be 3 to 50 characters, and a user can own only one team (createTeam.ts:10-26, "You can only have 1 team").

</Step>
<Step title="Convert your account">
Click **Convert to a Team Account**. Enter a team display name, check the acknowledgment checkbox, and click **Convert to a Team Account** to confirm.
</Step>
</Steps>

<Note>
To delete your team, scroll to the bottom of the **Team** page and click **Delete Team**. This reverts your account to a personal account. All members are removed, but your resources remain unchanged.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deleting a team is owner-only, not admin.

if (teamToDelete.ownerId !== context.auth.originalUserId) throw 'Only the team owner can delete the team.' (model/src/team/deleteTeam.ts:27-28). A team admin who is not the owner cannot do this.

Two other omissions: clicking Delete Team opens a confirmation dialog, and pending invites are cancelled along with memberships (TeamInvite.team ... onDelete: Cascade).

Suggested change
To delete your team, scroll to the bottom of the **Team** page and click **Delete Team**. This reverts your account to a personal account. All members are removed, but your resources remain unchanged.
Only the team owner can delete a team. To do so, scroll to the bottom of the **Team** page, click **Delete Team**, and confirm in the dialog. This reverts your account to a personal account. All members are removed and any pending invites are cancelled, but your resources remain unchanged.

</Note>

## Invite team members

Only admins can invite new members. Each invitation is tied to a specific email address and can only be accepted by the user with that address.

Check warning on line 26 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L26

In general, use active voice instead of passive voice ('is tied').

Check warning on line 26 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L26

In general, use active voice instead of passive voice ('be accepted').

<Steps>
<Step title="Open the Team page">
Go to the [Team page](https://console.runpod.io/team) in the Runpod console.
</Step>
<Step title="Send the invitation">
In the **Members** section, click **Invite new member**. Select a role, enter the member's email address, and click **Create Invite**.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The team-invite screenshot from the old page (create-team-invite-dialog-d8cb3fc6.png, "Create Team Invite dialog showing role selection and required email field") was removed and not re-added anywhere. This step is where it belongs. Confirmed it appears nowhere on the branch.

</Step>
<Step title="Share the invitation link">
The invitation link appears under **Pending Invites**. Copy it and share it with the invitee, or they will receive an email with a direct link to accept.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Casing: the section heading on the page is Pending invites, lowercase i (TeamSettings/index.tsx:187). The modal body text uses "Pending Invites", which is probably where this came from.

Also worth noting the section only renders once at least one invite exists, so a first-time admin will not see it before sending one.

</Step>
</Steps>

To invite multiple members at once, click **Bulk Invite**. Upload a CSV file or paste content directly using the format `role,email`, one member per line. A header row is detected automatically. Click **Send Invites** when done.

Check warning on line 40 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L40

In general, use active voice instead of passive voice ('is detected').

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three corrections to the bulk invite flow.

  1. The send button carries a live count, e.g. Send 3 Invites. It only reads "Send Invites" when there are zero valid rows, and is disabled in that state (BulkInviteForm.tsx:215-217).
  2. Header auto-detection only fires when the first cell lowercases to role (csvParser.ts:26-28). An email,role header is therefore not detected and parses backwards, since the parser takes cells[0] as role and cells[1] as email. Worth saying the header must start with role.
  3. Undocumented but user-visible: the cap is 300 invites per batch (createBulkTeamInvites.ts:23-25), and rows with errors are flagged in the preview and skipped rather than blocking the batch.
Suggested change
To invite multiple members at once, click **Bulk Invite**. Upload a CSV file or paste content directly using the format `role,email`, one member per line. A header row is detected automatically. Click **Send Invites** when done.
To invite multiple members at once, click **Bulk Invite**. Upload a CSV file or paste content directly using the format `role,email`, one member per line, up to 300 per batch. A header row is detected automatically if its first column is `role`. Rows with errors are flagged in the preview and skipped. Click **Send** when done; the button shows the number of valid rows, for example **Send 3 Invites**.


Invitation links remain active until used or manually revoked.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wrong: team invites expire after 3 days.

const expiresAt = addDays(now, 3) (model/src/team/createTeamInvite.ts:74, and the bulk path at createBulkTeamInvites.ts:121), enforced on accept (joinTeam.ts:26, "This invite has expired.").

You may be thinking of org invites, which are 14 days. The constant says so explicitly: // Org invites expire after 14 days (longer than TeamInvite's 3-day window...) (model/src/org/invite/constants.ts:1-3).

Suggested change
Invitation links remain active until used or manually revoked.
Invitation links expire 3 days after they are created. They also become invalid once used or manually revoked.


## Join a team

When invited to a team, you'll receive an invitation link from an admin.

Check warning on line 46 in teams/manageteams.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/manageteams.mdx#L46

Use 'administrator' instead of 'admin'.

<Steps>
<Step title="Open the invitation link">
Click the link provided by the team admin.
</Step>
<Step title="Accept the invitation">
Select **Join Team** to accept.
</Step>
</Steps>

Your account gains access to the team's resources based on the role assigned to you.

## Next steps

- [Create API keys](/get-started/api-keys) for programmatic access to Runpod services.
- [Deploy a Pod](/pods/manage-pods) to start using GPU resources.
- [Set up Serverless endpoints](/serverless/overview) for scalable AI inference.
40 changes: 40 additions & 0 deletions teams/teamroles.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
---

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the LIX score (56.17) below 35.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the SMOG grade (11.70) below 10.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the Flesch–Kincaid grade level (11.76) below 8.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the Automated Readability Index (14.10) below 8.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the Coleman–Liau Index grade (15.32) below 9.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the Gunning-Fog index (11.04) below 10.

Check warning on line 1 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L1

Try to keep the Flesch reading ease score (43.99) above 70.
title: "Roles and permissions"
sidebarTitle: "Roles and permissions"
description: "Understand the four built-in team roles in Runpod: Admin, Billing, Dev, and Basic. Learn what each role can access and manage."

Check warning on line 4 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L4

Use 'administrator' instead of 'Admin'.
---

Teams have four built-in roles. Each role is designed for a specific set of responsibilities and grants access accordingly. Assign the minimum role necessary for each member's work, and review team membership regularly to remove access for members who no longer need it.

Check warning on line 7 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L7

In general, use active voice instead of passive voice ('is designed').

| Permission | Basic | Billing | Dev | Admin |

Check warning on line 9 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L9

Use 'administrator' instead of 'Admin'.
|---|---|---|---|---|
| Access team account | ✅ | ✅ | ✅ | ✅ |
| Connect to existing Pods | ✅ | ❌ | ✅ | ✅ |
| Create, delete, start, and stop Pods | ❌ | ❌ | ✅ | ✅ |
| Create and delete Serverless endpoints | ❌ | ❌ | ✅ | ✅ |
| Send requests to Serverless endpoints | ✅ | ❌ | ✅ | ✅ |
| Connect to existing Instant Clusters | ✅ | ❌ | ✅ | ✅ |
| Create, delete, start, and stop Instant Clusters | ❌ | ❌ | ❌ | ✅ |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dev should be white-check, not cross.

Team Dev holds CLUSTER_MANAGE (model/src/authz/roleGrid.ts:511), and cluster create/delete/update/expand gate on CLUSTER:CREATE/DELETE/UPDATE (node/graphql/schema/cluster.ts:276,286,289). The console agrees: cluster delete is [ADMIN, DEV] (features/Clusters/ClusterCard/index.tsx:57).

| Create, update, and delete network volumes | ❌ | ❌ | ✅ | ✅ |
| View billing information | ❌ | ✅ | ❌ | ✅ |
| Manage payment methods | ❌ | ✅ | ❌ | ✅ |
| Invite team members | ❌ | ❌ | ❌ | ✅ |
| Manage team permissions | ❌ | ❌ | ❌ | ✅ |
| Modify team account settings | ❌ | ❌ | ❌ | ✅ |
| Access audit logs | ❌ | ❌ | ❌ | ✅ |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct as written today, but about to change.

Admin-only matches the backend right now: only the team admin row holds AUDIT_LOG_VIEW_SELF (roleGrid.ts:467) and the resolver gates on AUDIT_LOG:LIST (node/graphql/schema/auditLog.ts:60).

runpod/RunPod#6176 grants it to all four roles, matching the org grid and the RBAC spec, which puts AUDIT_LOG LIST on all roles. If that lands before this page ships, every cell in this row becomes a check.

Worth confirming merge order before publishing. Separately, the console has shown this nav item to team Dev the whole time (console/src/utils/routes.tsx:227, [ADMIN, DEV]), so a Dev currently sees the link and gets an error. #6176 resolves that too.


## Basic

The Basic role provides access to the team account and existing compute resources. Basic members can connect to running Pods and send requests to Serverless endpoints, but cannot create resources, view billing, or change account settings.

Check warning on line 28 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L28

Use 'can't' instead of 'cannot'.

## Billing

The Billing role is for financial management only. Billing members can view billing information and manage payment methods but have no access to compute resources.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"No access to compute resources" is not accurate, before or after my backend change.

Today, team Billing holds CRA:CREATE/UPDATE/DELETE (roleGrid.ts:531), so it can create, edit and delete the container registry credentials that Pods and Serverless workers use to pull private images. Dev cannot. It also holds CLUSTER:LIST and ENDPOINT:LIST.

runpod/RunPod#6176 removes those writes, but Billing still ends up able to read compute: pods, network volumes, templates, clusters and endpoints, mirroring org billing, whose purpose is explaining spend.

So the sentence needs changing either way. Suggested wording that holds after #6176:

Suggested change
The Billing role is for financial management only. Billing members can view billing information and manage payment methods but have no access to compute resources.
The Billing role is for financial management. Billing members can view billing information and manage payment methods. They can also view compute resources such as Pods, endpoints, and network volumes in order to understand spend, but cannot create, modify, or connect to them.

The table is also missing a container registry credentials row, which is where the Billing and Dev difference actually shows up. Worth adding once #6176 settles the values.


## Dev

The Dev role extends Basic with full compute resource management. Dev members can create, start, stop, and delete Pods, Serverless endpoints, and network volumes, but cannot access billing or account settings.

Check warning on line 36 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L36

Use 'can't' instead of 'cannot'.

## Admin

Check warning on line 38 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L38

Use 'administrator' instead of 'Admin'.

The Admin role has complete control over the team. Admins can manage members, configure account settings, handle billing, and control all compute resources.

Check warning on line 40 in teams/teamroles.mdx

View check run for this annotation

Mintlify / Mintlify Validation (runpod-b18f5ded) - vale-spellcheck

teams/teamroles.mdx#L40

Use 'administrator' instead of 'Admin'.
Loading