Roles
Application users and service accounts belong to a role. The following table lists the privileges associated with each role.
| Role → Privilege ↓  | 
Advanced | Admin | Owner | 
|---|---|---|---|
| Manage workflows | YES | YES | YES | 
| See system workflows | NO | NO | YES | 
| Manage public runtimes | YES | YES | YES | 
| Manage private runtimes | YES* | YES* | YES* | 
| Manage API keys | YES | YES | YES | 
| Browse JavaScript templates | YES | YES | YES | 
| See system components in the workflow editor | NO | NO | YES | 
| Upload and download custom components' manifests | YES | YES | YES | 
| Delete custom components' manifests | NO | NO | YES | 
| Browse users | NO | YES | YES | 
| Create users with the Advanced role | NO | YES | YES | 
| Create users with any role | NO | NO | YES | 
| Change the role of a user | NO | NO | YES | 
| Manage service accounts | NO | NO | YES | 
| Perform operations not listed above | YES | YES | YES | 
* Based on ownership and permissions, see the article about this topic.