# Roles & Permissions

SpaceKeep uses a role-based authorization system to control what administrators can do.

## Admin roles

| Role | Description |
| --- | --- |
| **Owner** | Full system access, including managing other owners |
| **Admin** | Full system access. Cannot manage owner accounts |
| **Moderator** | Community and content moderation only |
| **Marketing** | Marketing console only |

## Role hierarchy

- **Owners** can manage all roles, including other owners
- **Admins** cannot manage owner accounts
- **Moderators** can only access moderation tools
- **Marketing** can only access the marketing console

## Permissions

Each role has a specific set of permissions:

### User management
- View users
- Manage users
- Suspend users
- Ban users
- View user activity

### Moderation
- View reports
- Manage reports
- Issue warnings
- Issue timeouts
- Suspend users
- Ban users
- Remove content
- View moderation history

### Marketing
- View marketing dashboard
- Manage campaigns
- Manage audiences
- Manage templates
- Send campaigns

### Platform
- View analytics
- Manage authentication
- System settings
- Manage roles
- Manage synthetic users

## Assigning roles

Only owners can assign and manage administrator roles. The last active owner cannot be demoted or removed.

## Related

- [Administration Overview](/administration/) — all admin areas
- [Moderation](/administration/moderation/) — moderation tools
