User roles in organizations
This article is for organizations with free сlassroom licenses. If your organization uses commercial licenses, you'll manage everything in the new, enhanced JetBrains Central Console. You can find detailed instructions in the JetBrains Central Console documentation.
Access to JetBrains Account is role-based. All users in organizations are divided into two groups:
- Users with no access to the organization: These are users who have a license assigned to them but don’t have access to the organization management. These users can have a JetBrains Account where they see the licenses.
- Users with full or partial access to the organization management: These users must have a JetBrains Account to access their organization. There, they see their assigned or purchased licenses, as well as a separate section for organization management. What exactly they see in this section depends on their role – viewer, purchaser, org admin, or team admin.
Each role that allows access to the organization includes permissions that define what users with that role can do in the organization. Each user can have multiple roles. In this case, the permissions from each role are combined.
Viewer
Viewers have read-only access to the organization. They can log in to JetBrains Account, open the organization management section, and see which products, licenses, teams, and subscriptions the organization has, but they cannot make any changes.
Use this role for stakeholders who need full visibility into your licenses and team structure without any risk of accidental changes.
Only org admins can add viewers to the organization's account.
Purchaser
Purchasers' role includes all the permissions of viewers, plus limited access to organization management, with a focus on buying and renewing licenses. They can open the organization profile, see licenses, products, and subscription details, and place orders for the organization. But they cannot change the organization's settings or manage license assignment.
This role is best suited for people in finance or procurement who need to handle purchases and renewals, while leaving day-to-day license assignment and configuration to admins.
Only org admins can add purchasers to the organization's account.
Org admin
The org admin role includes all permissions of viewers and purchasers, as well as access to manage orders, licenses, and settings for the entire organization. They can buy and upgrade licenses across all teams, track orders, create and merge teams, assign licenses to users, and invite new org admins and team admins.
This role is intended for people who are responsible for overall license management and governance.
Only org admins can add new org admins to the organization's account.
Team admin
Team admins manage orders and licenses for their specific teams. They can also change their team's settings. Each team can have multiple admins.
Team admin is a good fit for users who need to manage licenses for their own group but do not need to access other teams or change organization-wide settings.
Org admins can add new team admins to any team. Team admins can add new team admins to their team.
Automatic assignment of roles
When you purchase JetBrains licenses for your organization, you can automatically get the org admin role if both of the following conditions are true:
- You are the only license purchaser.
- You used the same email address for all purchases for your organization.
So if you have a JetBrains Account registered with the email address you used to purchase the licenses, or if you create one later, you’ll be assigned the org admin role.
If you're not the first to purchase licenses for your organization but create a new team at checkout, you get the team admin role. You also become a team admin for any new team you create in the organization's account.
Assign roles to users
| 🔒 Permissions required: org admin. |
If you want to give a new user access to your organization, you need to invite them to the organization's JetBrains Account. To do that:
- Log in to your JetBrains Account.
- In the menu on the left side, click your organization's name.
- Click Administration.
-
In the upper-right corner, click the Invite Administrator, Invite Purchaser, or Invite Viewer button depending on the level of access you want to grant them.
To add new team admins, refer to Add or remove team admins
- In the dialog that opens, review the list of permissions you’re about to grant to your invitee and then check the box next to I agree to give the permissions mentioned above to the new Administrator/Purchaser/Viewer.
-
You’ll see the invitation text. Click Copy to copy it to your clipboard, or select Go to email client to open it in your default email app. You can then share the invitation via email, instant messaging, or any other method you prefer.
Change users' roles
| 🔒 Permissions required: org admin. |
You can expand or limit users' access to the organization by changing their role. Users can have multiple roles.
- Log in to your JetBrains Account.
- In the menu on the left, click on your organization's name.
- In the menu that opens, select Administration.
- Under Users with access to company licenses, you’ll see a list of users who have roles in your organization. Find the user whose role you want to change and click the edit button next to their current role.
- In the dialog, check or uncheck the boxes next to the roles you want to remove or add.
- Click Save.
Revoke users' roles
| 🔒 Permissions required: org admin. |
- Log in to your JetBrains Account.
- In the menu on the left, click on your organization's name.
- In the menu that opens, select Administration.
-
Under Users with access to company licenses, you’ll see a list of users who have roles in your organization. Find the admin you want to remove and click Remove access.
If you’d like to revoke your own administrator role, select Leave.
- Confirm your action in the dialog that appears.
Permissions
Here's what different roles allow you to do:
| Viewer | Purchaser | Org admin | Team admin | |
| View organization management section in JetBrains Account | ✔ |
✔ |
✔ |
|
| Manage the organization’s settings |
|
|
✔ |
|
| Add or remove org admins, purchasers, or viewers in the organization |
|
|
✔ |
|
| Add or remove team admins |
|
|
✔ |
✔ |
| View all teams | ✔ |
✔ |
✔ |
|
| Create teams |
|
|
✔ |
✔* |
| Manage team settings |
|
|
✔ |
✔ |
| Merge teams |
|
|
✔ |
|
| Transfer licenses between teams |
|
|
✔ |
✔* |
| Manage contacts |
|
|
✔ |
|
| Assign and revoke licenses from users |
|
|
✔ |
✔* |
| Renew subscriptions and subscription packs |
|
✔ |
✔ |
✔* |
| Enable or disable automatic renewal of subscriptions |
|
✔ |
✔ |
✔* |
| Manage subscription packs |
|
✔ |
✔ |
✔* |
| Cancel subscriptions |
|
✔ |
✔ |
✔* |
| Manage verified domains |
|
|
✔ |
|
| Generate API tokens |
|
|
✔ |
|
*Team administrators' permissions are limited to their respective teams. They also have limitations when creating new teams and transferring licenses. Please refer to the corresponding pages for more information.