Dropstone Support

Roles and permissions

The six roles in a Dropstone organization, what each one may do, why reading member conversations is deliberately not an administrator power, how administrators are appointed, and what the gold verified mark means.

Available onFreeProMaxEnterpriseRoles are set by the owner.

An organization has six roles. A role decides what a person can see and change in the organization dashboard, and the split between them is deliberate rather than a ladder.


The six roles

RoleWhat it is for
OwnerEverything, including the data settings, single sign-on, and billing. Can rename or close the organization and transfer ownership
AdminMembers and policies: who is in the organization and what they may use
SecurityThe security settings, and reading the conversation archive
BillingInvoices, seats, and the subscription. Nothing about policy
MemberTheir own work. No administrative access
AuditorReads everything, changes nothing

The six roles are what ships. An organization large enough to need a different split can ask for one: additional roles are added on request, and what can be added depends on the size of the organization. Get in touch and we will tell you what is possible.


The role card

The organization's mark beside your name in the console sidebar opens your role as a card. It names the role the way the rest of the industry does, says what the role is for, and lists what it may do section by section:

Organization owner

Rohan Mehta · Blankline

Full control. Cannot be removed; ownership must be transferred.

Access

Members and seats
Manage
Billing and payment
Manage
Policy and model access
Manage
Security and sign-on
Manage
Audit log
View
Organization usage
View

Rohan Mehta owns and administers Blankline. Confirmed by Dropstone. Enforced on every request, not only in this console.

The list is the same permission model the console enforces, so the card cannot claim more than the role has. Manage is change, View is read, and No access means the role does not reach that section. The last line says how the role is held, and that it is enforced on every request.


Two separations worth knowing

Reading member conversations is not an administrator power. It belongs to the owner, the security role, and auditors. The person who onboards staff is not the person who can read what they wrote, and that is the point.

Billing and policy do not come as a pair. The billing role can see invoices and seats and cannot touch the model or connector allowlists, because those are a different kind of decision.

An auditor can read everything in the dashboard and is blocked from writing anything.


Appointing an administrator

The owner adds people and sets their role from Members. Ownership is not something you invite someone into: ownership is transferred, not invited, and moving it is a deliberate act by the current owner.


The verified mark

An organization that Dropstone has reviewed and approved carries a gold verified mark. It asserts that the organization was reviewed, not that any particular claim it makes is true.

The mark follows the organization, not the person. Beside your name it says you are affiliated with a verified organization; beside the organization it says the organization is verified. It appears next to the organization's own mark, and the two say different things:

RRohan MehtaBlanklinerohanmehta@blankline.org

The gold mark is a status: Dropstone confirmed that the domain belongs to the company and approved the organization for enterprise operations. The organization's mark is identity: it says which organization provides your seat, and it claims nothing. The same row, with the same two marks, appears in the chat sidebar, the console sidebar, and Settings.

Clicking the gold mark opens the card that says what was checked:

Affiliated with Blankline

Rohan Mehta is a confirmed member of Blankline, a Dropstone-verified organization.

R

Rohan Mehta

Organization owner · Blankline

rohanmehta@blankline.org

Rohan Mehta owns and administers Blankline. Confirmed by Dropstone.

About verification

It reads Affiliated with Blankline because the claim is about the organization and never about you: a member of a verified organization is a confirmed member, not a verified person.


When the mark is missing

The mark is shown while the organization is active and nothing is paused: requests are served, and the owner has full control. It is removed when any one of these is true:

  • The organization is not active. On hold, suspended, cancelled, and terminated all remove the mark, and requests stop at the same time. Organization status: what each one means explains each state and what clears it.
  • The domain has not been verified. The mark asserts that the domain belongs to the company, so a domain that has not been checked leaves nothing to assert.
  • The organization is not on an enterprise agreement.

If you expected the mark and it is not there, check the organization's status in the dashboard: the blocked screen names the state, the reason, and since when. Then write to enterprise@blankline.org.

A hold and a suspension can be reviewed, and the mark returns with access. A cancellation and a termination end the agreement, so no review reverses them.


Related articles

Ctrl+I