Roles & Quotas
Organization roles, permissions, and resource quotas.
Organization Roles
ArmorIQ has five built-in roles with different permission levels:
| Role | Description | Key Permissions |
|---|---|---|
| Organization Admin | Full access to all features | Everything — manage members, servers, agents, policies, settings |
| IAM Admin | Identity and access management | User management, role assignment, access control, view all |
| Developer | Build and deploy | Register MCP servers and agents, manage proxy, monitor, view all |
| Analyst | Security analysis | View vulnerabilities, run scans, generate reports, view all |
| Viewer | Read-only access | View dashboards, reports, and logs only |
Detailed Permission Matrix
| Permission | Org Admin | IAM Admin | Developer | Analyst | Viewer |
|---|---|---|---|---|---|
| Manage team members | ✅ | ✅ | ❌ | ❌ | ❌ |
| Assign roles | ✅ | ✅ | ❌ | ❌ | ❌ |
| Access control settings | ✅ | ✅ | ❌ | ❌ | ❌ |
| Register MCP servers | ✅ | ❌ | ✅ | ❌ | ❌ |
| Register agents | ✅ | ❌ | ✅ | ❌ | ❌ |
| Deploy agents | ✅ | ❌ | ✅ | ❌ | ❌ |
| Manage proxy | ✅ | ❌ | ✅ | ❌ | ❌ |
| Monitor resources | ✅ | ❌ | ✅ | ❌ | ❌ |
| View vulnerabilities | ✅ | ❌ | ❌ | ✅ | ❌ |
| Run scans | ✅ | ❌ | ❌ | ✅ | ❌ |
| Generate reports | ✅ | ❌ | ❌ | ✅ | ❌ |
| View all (read-only) | ✅ | ✅ | ✅ | ✅ | ✅ |
Role-Based Dashboard
Different roles see different dashboard views and sidebar navigation:
- Organization Admin / IAM Admin / Developer / Analyst — Full Security Dashboard with complete sidebar navigation including all asset registries, policy tools, industry products, and administration sections.
- Viewer — Simplified Dashboard with restricted sidebar. Includes read-only access to: Dashboard, MCP Registry, Agent Registry, Intent Plans, AIQraph, Quick Scan, Policy Studio, API Keys, OPA Dashboard, Audit Logs, and Settings.
Admin-Only Features
The following features require Organization Admin or equivalent permissions:
- Add Agent / Add MCP Server
- ArmorPay Dashboard and Studio
- ArmorHealth Dashboard and Studio
- Policy Bundle Studio
- OPA Dashboard
- Product Preferences
Organization Quotas
Each organization has resource limits:
| Resource | Default Limit |
|---|---|
| Team Members | 5 |
| MCP Servers | 2 |
| Agents | 4 |
| Proxy Servers | 2 |
| Policies | 2 |
| API Keys | 10 |
Quota limits are enforced in the UI. For example, the "Invite Member" button is disabled when you've reached the team member limit. Contact ArmorIQ support to increase quotas.