Permissions matrix
Seats and roles
Seats and roles are related, but they control different things.- Seats control which GitHub users are assigned cubic access and how usage is counted for billing.
- Roles control what a seated user can change inside cubic.
How to become an admin
There are three ways to become a cubic admin:- Install the cubic GitHub app. When you install cubic for your GitHub organization, you automatically become an admin.
- Be a GitHub organization admin. GitHub organization admins automatically become cubic admins when the app is installed.
- Get promoted by an existing admin. Any current admin can promote you through subscription settings.
Admin role
Admins have full control over team management and can:- Manage seat assignments: Add or remove cubic seats for team members
- Manage roles: Change members between admin, member, and viewer roles (note: bot accounts cannot be admins)
- Configure workspace settings: Change AI review settings, repository settings, integrations, scan settings, and billing automation
- Configure auto-assign: Enable automatic seat assignment and removal when GitHub organization members join or leave
- Manage billing: Update plans, seats, and subscription controls
- Bulk actions: Select multiple users to manage seats and roles in bulk
Member role
Members can use cubic’s full feature set and edit non-billing settings:- Full platform access: Use all cubic features including AI reviews, analytics, and PR management
- Manage workspace settings: Configure AI review behavior, repository settings, integrations, scan settings, and other non-billing team settings
- View billing status: See subscription status and billing-related information without changing billing details
- No seat, role, or billing management: Cannot assign/remove seats, change user roles, or manage billing and subscription controls
Viewer role
Viewers can use cubic’s review and analytics surfaces, but they cannot change cubic settings:- View team information: See team members, role assignments, subscription status, and settings
- Use review surfaces: Access PR review, analytics, and other non-settings views available to their seat
- No configuration changes: Cannot change AI review settings, repository settings, integrations, seats, roles, or billing controls
How to manage user roles
Only admins can change user roles. cubic provides both individual and bulk role management:Individual role changes
To promote or demote a single user:- Navigate to Settings → Subscription
- Find the team member in the list
- Click the three-dot menu (⋮)
- Select the new role: Admin, Member, or Viewer
- The change takes effect immediately
Only admins can see and use seat and role management options. Members and viewers can view the team list, but they cannot change seats or roles.
Bulk role changes
To change roles for multiple users at once:- Navigate to Settings → Subscription
- Use the checkboxes to select multiple team members
- Click “Update role” in the bulk action bar
- Choose the role to apply to the selected users
- All selected users are updated immediately