Sume team roles: who can run, edit, archive or pay
A Sume team workspace has three capability roles. Admin does everything, Creator creates and runs, Member is view-only. Here is the full table.

In a Sume team workspace, **Admin** can do everything, **Creator** can create, edit and run, and **Member** can read the shared libraries and open threads but cannot run or write. Clerk owners map to Admin. The mirrored billing role maps to Member today, so paying is Admin-only. The table below is the one the code checks.
The capability table
Every gate in the web app asks one function, can(role, capability), defined in apps/web/lib/workspaces/capabilities.ts. Here are the values for the capabilities that matter most day to day.
| Capability | Admin | Creator | Member |
|---|---|---|---|
| Read shared Product, Action, Skill and Asset libraries | yes | yes | yes |
| Create and edit a Product, Action or Skill | yes | yes | no |
Run an Action or a generation (action.run) | yes | yes | no |
| Message and run an agent turn on a team chat | yes | yes | no |
| Connect or disconnect an integration | yes | yes | no |
| Archive a resource you created | yes | yes | no |
| Archive anyone's resource | yes | no | no |
| Invite, remove or re-role members | yes | no | no |
| Manage the wallet, top-ups and subscription | yes | no | no |
| Rename the team handle, edit the team profile | yes | no | no |
| Read every member's usage event rows | yes | no | no |
Three vocabularies collapse into three roles
Clerk stores five membership values: owner, admin, creator, member and billing. The product only uses three. owner and admin become Admin, creator stays Creator, and member and billing become Member. The billing value is not provisioned on the Clerk instance and the team wallet was shipped Admin-only, so a finance-only role does not exist yet.
One name trap: an isCreator flag in the membership mirror means the person who created the organization. It promotes that person to owner and has nothing to do with the Creator role.
Archive is split on purpose
Creators can edit any workspace resource but archive only the ones they made. The check reads created_by_user_id, not the workspace owner, because a workspace-owned resource has no personal owner. Admins can archive any resource. A resource stays on the workspace when its author leaves; it does not follow the member out.
API keys and webhooks follow the same ladder
A team API key spends as the team, and the API itself cannot tell roles apart, so the web routes gate the developer surfaces. Minting a team key, playground writes and Fastlane publishing need action.run. Reading or rotating a webhook signing secret, sending a test delivery or redelivering needs integrations.manage, which Creators have and Members do not. Listing keys, deliveries and connections works for any member. Revoking a team key needs archive-any, or being the person who made it.
What to do with it
Give most producers Creator. Keep Admin for the person who funds the wallet and manages people. Use Member for reviewers and stakeholders who should see the library and watch live jobs without being able to spend. Personal workspaces resolve to Admin, so none of this changes for a solo account.
Where generated media ends up
When a Creator or Admin runs an Action or a generation in team context and it produces durable media, Sume saves it to the workspace Asset library with the organization as workspace and the acting member recorded as creator. Every member can read it. There is no publish step, and the team docs openly accept some library clutter from Creator runs as expected behavior. Per-user hiding and likes exist to tame it.
The Agents Assets view is a union of job snapshots, thread media and direct uploads, de-duplicated by normalized media URL, so one clip can appear from several origins and still show once. Thread-only attachments stay with their thread unless a run publishes them. Pins in the sidebar are per device and are never shared with teammates, so do not use them as a team bookmark.
Related posts
More in Use cases
- Ten 15-second UGC-style avatar ads: $27.60 on Sume vs Creatify
Ten 15-second talking-avatar ads at the standard tier cost $27.60 on Sume. Creatify lists Starter at $39 with 100 credits and Pro at $99 with 5 seats.
- Ten candidate photos for one avatar: rejects create no job
Screen ten candidate photos for one Sume avatar with free preflight failures. Only accepted photos create a $0.95 avatar job. Includes a guarded Python script.
- Ten FAQ answer clips from one avatar: cost and re-rendering one
Ten 20-second answers from one Sume avatar cost $49 at plus quality plus $0.95 for the avatar. When one answer changes, you re-render only that clip, for $4.90.
- Ten hook variants of a 9:16 ad from one curl loop on Seedance 2.5
Ten opening hooks, one shared body prompt, ten Video Router jobs. A shell loop with stable Idempotency-Keys and how to plan the cost of 12-second 9:16 clips.
Written by Sume