---
title: RBAC role types
description: Understand the RBAC roles available in n8n, and the access they have.
contentType: reference
---

# RBAC role types

/// info | Feature availability
* The Project Editor role is available on Pro Cloud and Self-hosted Enterprise plans. 
* The Project Viewer role is only available on Self-hosted Enterprise and Cloud Enterprise plans.
///

Within projects, there are three user roles: Admin, Editor, and Viewer. These roles control what the user can do in a project. A user can have different roles within different projects.

## Project Admin

A Project Admin role has the highest level of permissions. Project admins can:

* Manage project settings: Change name, delete project.
* Manage project members: Invite members and remove members, change members' roles.
* View, create, update, and delete any workflows, credentials, or executions within a project. 

## Project Editor

A Project Editor can view, create, update, and delete any workflows, credentials, or executions within a project. 

## Project Viewer

A Project Viewer is effectively a `read-only` role with access to all workflows, credentials, and executions within a project.

Viewers aren't able to manually execute any workflows that exist in a project. 

/// note | Role types and account types
Role types and [account types](/user-management/account-types.md) are different things. Every account has one type. The account can have different role types for different [projects](/user-management/rbac/projects.md).
///

| Permission | Admin | Editor | Viewer | 
| ---------- |------ | ------ | ------ | 
| View workflows in the project | :white_check_mark: | :white_check_mark: | :white_check_mark: |
| View credentials in the project | :white_check_mark: | :white_check_mark: | :white_check_mark: |
| View executions | :white_check_mark: | :white_check_mark: | :white_check_mark: | 
| Edit credentials and workflows | :white_check_mark: | :white_check_mark: | :x: | 
| Add workflows and credentials | :white_check_mark: | :white_check_mark: | :x: | 
| Execute workflows | :white_check_mark: | :white_check_mark: | :x: | 
| Manage members | :white_check_mark: | :x: | :x: | 
| Modify the project | :white_check_mark: | :x: | :x: | 
| Use external secrets in credentials | :white_check_mark:* | :white_check_mark:* | :x: |
| Manage project secret vaults | :white_check_mark:* | :x: | :x: |

\* Requires **Enable external secrets for project roles** to be enabled by an instance owner or admin. Refer to [Access for project roles](/external-secrets.md#access-for-project-roles). This is available from n8n version `2.13.0`.

[Variables](/code/variables.md) and [tags](/workflows/tags.md) aren't affected by RBAC: they're global across the n8n instance.
