Appearance
Account & Role Types
VeriPrompt uses a layered access model. Every user has a user role that determines their platform-level capabilities, and can additionally be assigned access profiles for fine-grained permission control. This page explains each layer and helps admins choose the right setup.
Account types
When you register, you pick an account type that determines your workspace size and feature set.
| Account Type | Best For | Limits |
|---|---|---|
| Individual | Solo developers, freelancers, personal projects | Single user |
| Team | Small teams (2-10 users) sharing prompts and routing | Shared billing, team projects |
| Enterprise | Large organizations with compliance, audit, and multi-team needs | Custom limits, SLA, advanced security |
You can upgrade from Individual to Team or Enterprise in Settings > Account.
Company types (deployment model)
Your company record also has a deployment type that affects how VeriPrompt is hosted and licensed.
| Company Type | Description | Example |
|---|---|---|
| Online | Standard SaaS on app.veriprompt.tech | Most customers |
| Offline | Air-gapped, on-premise installation with no internet access | Banks, defense, classified environments |
| Personal | Individual accounts without a company entity | Freelancers, hobbyists |
| Reseller | Partner who resells VeriPrompt SaaS subscriptions to their own clients | Consulting firms, MSPs |
| Reseller Offline | Partner who deploys on-premise VeriPrompt for their clients | System integrators in regulated industries |
User roles
Every user is assigned exactly one role. Roles are hierarchical: higher roles can manage lower ones.
Platform-level roles
These roles are reserved for VeriPrompt platform operations. Normal company admins cannot assign them.
| Role | Purpose | Who uses it |
|---|---|---|
| Super Admin | Full platform access across all companies. Can generate licenses, impersonate users, and manage platform settings. | VeriPrompt HQ staff only |
| Instance Admin | Top administrator for an on-premise installation. Full control of that instance. | IT admins running self-hosted VeriPrompt |
| SaaS Admin | Legacy alias for Instance Admin in SaaS deployments. Functionally identical. | Older installations only |
Company-level roles
These are the roles you assign to users within your company workspace.
| Role | Purpose | Typical person |
|---|---|---|
| Account Owner | Highest authority within a company. Can manage billing, subscription, all users, and all settings. One per company. | CEO, CTO, or whoever purchased the plan |
| Account Admin | Full company administration. Same as Account Owner except cannot manage billing or assign owner-level roles. | IT lead, department head |
| Accountant | View-only access to billing, invoices, and usage reports. Cannot modify settings or users. | Finance team, bookkeeping |
| Manager | Manages teams and projects. Can assign tasks and view analytics but cannot modify company-wide settings. | Team lead, project manager |
| Security Custodian | Monitors security, reviews audit logs, and manages incident reports. Focused on compliance oversight. | CISO, DPO, compliance officer |
| Synthetic Admin | Full access to synthetic prompt testing: create, schedule, and manage test campaigns. | QA lead, prompt testing manager |
| Synthetic Operator | Can run and view synthetic tests but cannot create or schedule new campaigns. | QA engineer, test operator |
| Developer | API access, prompt building, and gateway usage. No admin functions. | Software engineer, integrator |
| Member | Team participant with limited access. Can view projects and use assigned prompts. | Business analyst, content writer |
| User | Basic chat access only. Can create conversations and run prompts but cannot manage anything. | End user consuming AI services |
Role assignment rules
Not every role can assign every other role. The matrix below shows who can assign whom:
| Assigner | Can assign |
|---|---|
| Super Admin | All roles |
| Account Owner | Account Admin, Accountant, Manager, Security Custodian, Synthetic Admin, Synthetic Operator, Developer, Member, User |
| Account Admin | Accountant, Manager, Developer, Member, User |
Roles not listed (e.g., Developer, Member) cannot assign roles to others.
Access profiles
Access profiles provide fine-grained permission control on top of roles. Every company gets three default profiles, plus built-in templates that admins can clone and customize.
Default profiles (created for every company)
| Profile | Authority Level | Description |
|---|---|---|
| Company Admin | 2 | Full access to all company features: users, billing, settings, prompts, routing, analytics, security. |
| Project Admin | 1 | Manages projects, teams, and day-to-day operations. Cannot change company settings, billing, or access profiles. |
| User | 0 | Core features only: chat, own prompts, basic analytics. Daily token limit: 100k. Monthly limit: 2M. |
Built-in templates (available for cloning)
| Profile | Best For | Key capabilities |
|---|---|---|
| Read-Only Analyst | Auditors and analysts who need visibility but should not change anything | View all data, export analytics and prompts, view audit logs, view billing. Cannot modify anything. |
| Prompt Designer | Prompt engineers focused on building and testing prompts | Full prompt management, synthetic testing, repository access, MCP tool access. No admin functions. |
| Security Auditor | Security and compliance reviewers | Full visibility into audit logs, encryption settings, security incidents, and blacklists. Can manage encryption and incidents. |
Custom profiles
Admins can create custom profiles by cloning any built-in template and adjusting individual permissions. Permissions are grouped into six clusters:
- AI Chat Client - Conversations, classifications, categories, credentials, blacklists
- Prompt Management - Create, edit, version, promote, share, encrypt, protect
- Gateway & Routing - Policies, providers, ranking, health monitoring, cost limits
- Projects & Teams - Project CRUD, repositories, branches, team management
- Analytics & Testing - Dashboards, synthetic tests, experiments, agents, workflows
- Account Admin - Users, access profiles, company settings, billing, security, API keys
Project and team roles
Within projects and teams, users get additional context-specific roles.
Project roles
| Role | Access |
|---|---|
| Owner | Full project control: settings, members, deletion |
| Maintainer | Edit project, manage branches, approve changes |
| Developer | Push code, create branches, submit change requests |
| Viewer | Read-only access to project content |
Team roles
| Role | Access |
|---|---|
| Owner | Full team management including deletion |
| Admin | Manage members and team settings |
| Member | Participate in team activities |
Collaboration roles (real-time editing)
| Role | Access |
|---|---|
| Owner | Full control over the shared resource |
| Editor | Can modify content |
| Viewer | Read-only access |
| Commenter | Can view and add comments but not edit |
Choosing the right setup: practical examples
Example 1: Small startup (5 people)
"We're a team of 5. Our CTO handles everything, two engineers build with the API, and two product managers just use chat."
| Person | Role | Access Profile |
|---|---|---|
| CTO | Account Owner | Company Admin |
| Engineer 1 | Developer | Project Admin |
| Engineer 2 | Developer | Project Admin |
| Product Manager 1 | User | User |
| Product Manager 2 | User | User |
Example 2: Enterprise with compliance requirements
"We have 200 employees. Legal needs audit access, the security team monitors everything, finance tracks costs, and engineering teams work on separate projects."
| Person / Group | Role | Access Profile | Notes |
|---|---|---|---|
| IT Director | Account Owner | Company Admin | Single owner, manages billing and subscription |
| 2 IT Admins | Account Admin | Company Admin | Day-to-day user and settings management |
| CISO | Security Custodian | Security Auditor | Reviews audit logs and incident reports |
| DPO | Security Custodian | Read-Only Analyst | Compliance monitoring without modification rights |
| Finance Lead | Accountant | Read-Only Analyst | Billing visibility, usage reports |
| Engineering Leads (4) | Manager | Project Admin | Each manages their team's projects |
| QA Lead | Synthetic Admin | Prompt Designer | Creates and schedules synthetic test campaigns |
| QA Engineers (3) | Synthetic Operator | User | Run tests assigned by the QA lead |
| Engineers (30) | Developer | Custom: "Senior Developer" | Clone Project Admin, add API key creation |
| Business Users (150) | User | User | Chat access with curated prompts |
Example 3: Consulting firm reselling VeriPrompt
"We're an IT consultancy. We resell VeriPrompt to 10 client companies and need to manage them centrally."
| Setup | Choice |
|---|---|
| Company Type | Reseller |
| Consultancy Admin | Account Owner with Company Admin profile |
| Client Admins | Account Admin per client company |
| Client End Users | User with default User profile |
Example 4: Regulated on-premise deployment
"We're a bank running VeriPrompt on-premise. No internet access. The infra team manages the instance."
| Setup | Choice |
|---|---|
| Company Type | Offline |
| Infra Lead | Instance Admin (manages the on-premise instance) |
| Department Head | Account Owner |
| Compliance Officer | Security Custodian with Security Auditor profile |
| Developers | Developer with custom profile limiting model access |
| Tellers / Staff | User with restricted token limits |
Next steps
- Registration - Sign up and choose your account type
- Account Management - Manage your workspace
- Service Tiers - See what features vary by plan
- Company Admin Guide - Full admin walkthrough
- Security Custodian Guide - Security and compliance setup
