Admin roles
- 阅读
- 4 分钟
- 类别
- Proton for business
If you have a subscription for any Proton Professional or Workspace plan, you can assign admin roles to members of your organization. Admin roles let you delegate administrative tasks without handing out full control, enabling different people to manage different parts of your business more efficiently and securely.
Other Proton plans use a binary user roles system, where users are either Administrators (with full administrative access) or Users (with no administrative access). For larger organizations that have several people managing accesses and settings, more granular permissions may be required. Admin roles cater to this by following the principle of least privilege, granting each role only the permissions it needs for a specific set of responsibilities.
Admin roles are available on the following plans:
- Mail Professional
- Drive Professional
- Pass Professional
- VPN Professional
- VPN and Pass Professional bundle
- Workspace bundles
- Proton Enterprise
In this article, we explain more about admin roles and how they work, including:
Types of admin roles
Proton supports three types of admin roles:
- Organization Admins have full access and can perform all administrative actions in the organization, including sensitive tasks. Every company must have at least one Organization Admin. This is the equivalent of an Administrator in plans without expanded admin roles.
- User Admins can manage members, including adding and removing them from the organization. User Admins can also manage groups and assign User Admin and Security Admin roles to others.
- Security Admins can manage organization security settings, such as password policies and two-factor authentication requirements, and have access to the activity monitor.
Users without any admin roles assigned are Users by default, and do not have any administrative privileges.
How to assign admin roles
Organization Admins and User Admins can assign roles to a single user or to a group, granting everyone in that group the same privileges.
Only Organization Admins and User Admins can assign roles for other users and groups, and change roles for the groups they belong to. You cannot edit your own role(s).
Assign a role to a user
- Log in to your administrator Proton Account at account.proton.me and go to Settings → All settings → Organization → Users and addresses.
- Click the name of the user you want to update, or the ⋮ icon next to their name and select Edit.
- In the modal, go to the Roles and permissions tab.
- Select one or more admin roles for the user, then click Save.

All done. The user’s role(s) will be updated automatically.
Assign a role to a group
Groups can be assigned User Admin or Security Admin roles, but not Organization Admin. Only Organization Admins and User Admins can assign roles to a group.
- Log in to your administrator Proton Account at account.proton.me.
- In the sidebar, go to Organization -> Groups. Select the desired group and click the Edit icon.
- In the modal, go to the Roles and permissions tab.
- Select one or more admin roles for the group, then click Save.

All done. The group’s role(s) will be updated, and everyone in the group will inherit permissions automatically.
How changing your plan affects admin roles
Access to admin roles is dependent on your plan, and upgrading or downgrading will automatically adjust its availability for your organization.
What happens if you upgrade your plan
If you upgrade to a plan that supports admin roles, the feature will be automatically unlocked for your organization. All users who currently hold the Administrator role will become Organization Admins. You can then assign more specific admin roles to your team.
What happens if you downgrade your plan
If you downgrade to a plan that doesn’t support admin roles, any Security Admin or User Admin roles that are already assigned will remain in place and continue to function, so no one unexpectedly loses access. However, the admin roles interface will become read-only, and you can remove existing role assignments but cannot assign new ones. Once no users and groups have the Security Admin or User Admin role assigned, the admin roles interface will be hidden and your organization automatically reverts to the standard Admin and User roles.