Permissions matrix
Seats and roles
Seats and roles are related, but they control different things.- Seats control which GitHub users are assigned cubic access and how usage is counted for billing.
- Roles control what a seated user can change inside cubic.
How to become an admin
There are three ways to become a cubic admin:- Install the cubic GitHub app. When you install cubic for your GitHub organization, you automatically become an admin.
- Be a GitHub organization admin. GitHub organization admins automatically become cubic admins when the app is installed.
- Get promoted by an existing admin. Any current admin can promote you through Members settings.
Admin role
Admins have full control over team management and can:- Manage seat assignments: Add or remove cubic seats for team members
- Manage roles: Change members between admin, member, and viewer roles (note: bot accounts cannot be admins)
- Configure workspace settings: Change AI review settings, repository settings, integrations, scan settings, and billing automation
- Configure auto-assign: Give a seat to developers who join the GitHub organization or open their first PR, and remove seats when members leave the GitHub organization
- Manage billing: Update plans, seats, and subscription controls
Member role
Members can use cubic’s full feature set and edit non-billing settings:- Full platform access: Use all cubic features including AI reviews, analytics, and PR management
- Manage workspace settings: Configure AI review behavior, repository settings, integrations, scan settings, and other non-billing team settings
- View billing status: See subscription status and billing-related information without changing billing details
- No seat, role, or billing management: Cannot assign/remove seats, change user roles, or manage billing and subscription controls
Viewer role
Viewers can use cubic’s review and analytics surfaces, but they cannot change cubic settings:- View team information: See team members, role assignments, subscription status, and settings
- Use review surfaces: Access PR review, analytics, and other non-settings views available to their seat
- No configuration changes: Cannot change AI review settings, repository settings, integrations, seats, roles, or billing controls
How to manage user roles
Only admins can change user roles. To promote or demote a user:- Navigate to Settings → Members
- Find the team member in the list, or search for them with Search people
- Click the row menu (⋯) and choose Change role
- Select the new role: Admin, Member, or Viewer
- The change takes effect immediately
Only admins can see and use seat and role management options. Members and viewers can view the
team list, but they cannot change seats or roles.
Manage roles through the API
Use the Members API to list members and update their seats and roles from your own scripts. With your personal API key, the API uses the same role permissions as the app. Admins create organization API keys in Settings → API, CLI & MCP, with read or admin access. A read key can read members, and an admin key can also update their seats and roles like an admin. Each key works only in its own organization and cannot change billing or the subscription. Updates need an organization admin or an organization key with admin access, and an active Team, Pro, or Max subscription billed through cubic.FAQ
I'm a GitHub admin. Why can't I manage billing in cubic?
I'm a GitHub admin. Why can't I manage billing in cubic?
Check your role in Settings → Members for the selected GitHub organization. Billing
requires the Admin role in cubic. GitHub organization admins receive that role during
installation, but later role changes are managed in cubic. Ask an existing cubic admin to
promote you. If you installed the app and have no admin access, contact
support with your GitHub username and organization.
I have a paid personal account. Does it cover my organization?
I have a paid personal account. Does it cover my organization?
Not automatically. Your personal GitHub installation and an organization’s installation are
separate. Check the selected organization and its subscription in Settings → Billing.
Contact support if you need help moving a subscription to the right
workspace.